brakeman
https://github.com/presidentbeef/brakeman
Ruby
A static analysis security vulnerability scanner for Ruby on Rails applications
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
3 Subscribers
Add a CodeTriage badge to brakeman
Help out
- Issues
- Apparently never ending "Indexing call sites..."
- dynamic render path check fires on component inheriting from ViewComponent::Base (but from a gem)
- Possible unprotected redirect for URL
- Trigger Mass Assignment rule on other foreign keys than account_id
- SQL injection false negative for connections on complex objects
- I get false positives for SQL injection on none AR classes on count.
- GitHub Actions report doesn't show where the error/warning occurs
- False Positive CSRF Warning for RAILS LTS 4.2.11.20
- False negative SQLi using map
- Add Check: CSS Injection within inline styling
- Docs
- Subscribe to help with docs for this repo and come back later