[LRUG] Keeping track of new security vulnerabilities?

Oliver Legg ollylegg at gmail.com
Fri Sep 20 02:15:27 PDT 2013


> Very cool (assuming the database of vulnerabilities is up to date). To turn this problem on its head, people who maintain gems: where would you submit the info that a gem has been updated with a security release?

I think bundler-audit and gemnasium use https://github.com/rubysec/ruby-advisory-db as their data source.




More information about the Chat mailing list