...endanger an app and how we find and fix them, e.g. with bundler-audit, CVE advisories and Rails LTS. You can explain what HTTPS guarantees against an attacker on the...

...for Rails projects — our card Vulnerable dependencies 📄 bundler-audit — checks your Gemfile.lock against known CVEs 📄 Brakeman — static analysis of a Rails app for security warnings 📄 How to apply security updates...

Best results in other decks

...dfsg-1.3build2.1) UNRELEASED; urgency=medium * SECURITY UPDATE: possible arbitrary file leak (CVE-2022-44268) * Backport upstream https://github.com/ImageMagick/ImageMagick6/commit/3c5188b41902a909e163492fb0c19e49efefcefe -- YOUR NAME <YOUR@EMAIL-ADDRESS> Sun, 05 Feb...

...dfsg-2.1ubuntu11.4.1) UNRELEASED; urgency=medium * SECURITY UPDATE: possible arbitrary file leak (CVE-2022-44268) * Backport upstream https://github.com/ImageMagick/ImageMagick6/commit/3c5188b41902a909e163492fb0c19e49efefcefe -- YOUR NAME <YOUR@EMAIL-ADDRESS> Sun, 05 Feb...

Usage The CLI will show you for each gem, whether a CVE exists for your current version and whether major/minor/patch updates are available. You can navigate the...

...we no longer recommend blindly installing patch updates. Prefer using this tool for patching CVEs and for catching up on major versions. The tool respects your Bundler settings, such as...

Search in all decks