brakeman
https://github.com/presidentbeef/brakeman
Ruby
A static analysis security vulnerability scanner for Ruby on Rails applications
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
3 Subscribers
Add a CodeTriage badge to brakeman
Help out
- Issues
- Do dataflow on all of 'library' code
- Possible false positive for unprotected redirect using Pundit policy_scopes
- Report on: allow_forgery_protection = false
- superclass mismatch for class Mark
- Ignore comment in Regex
- Cross-Site Scripting - Unescaped Parameter Value false negatives
- Namespaced classes that are not fully qualified can cause difference in false positives/negatives (WIP)
- Brakeman fails to find strong parameters if the protected attributes gem is installed
- More granularity to --no-exit-on-warn
- Invalid Synopsis Email in LICENSE.md
- Docs
- Subscribe to help with docs for this repo and come back later