TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Is it vulnerable? Drag-n-drop your Gemfile.lock to check

175 pointsby phillmvalmost 10 years ago

11 comments

sciurusalmost 10 years ago
You can run this check yourself using the bundle-audit tool. It uses the list of vulnerabilities from ruby-advisory-db.<p>Checking the git history, I see that phillmv is a contributor to ruby-advisory-db.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;bundler-audit" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;bundler-audit</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;ruby-advisory-db" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;ruby-advisory-db</a>
评论 #10022993 未加载
phillmvalmost 10 years ago
Hey. We posted about our service last week and got great feedback. We took that feedback and decided to put isitvulnerable.com together to really showcase what you can get out of it &#x2F; uh check your dang Gemfile.lock at least.<p>We&#x27;re expanding platforms, so do tell us what to support next :).
评论 #10022807 未加载
评论 #10023236 未加载
评论 #10022964 未加载
评论 #10023485 未加载
评论 #10024893 未加载
评论 #10022906 未加载
Mojahalmost 10 years ago
If you&#x27;re into PHP, SensioLabs has a similar service you can use in your Composer.lock file: <a href="https:&#x2F;&#x2F;security.sensiolabs.org&#x2F;check" rel="nofollow">https:&#x2F;&#x2F;security.sensiolabs.org&#x2F;check</a><p>It&#x27;ll block any vulnerable version of a dependency in your project.
homakovalmost 10 years ago
Someone should reestimate severity of those &quot;CVEs&quot;. I got 10 warnings and none of them is any severe for my app(and yours too, likely), so I&#x27;m definitely not vulnerable.<p>Also LOL &quot;CSRF Vulnerability in jquery-rails&quot; is known as not a bug at all.
评论 #10024781 未加载
bshimminalmost 10 years ago
This is terrific. Easy to understand, fast, and very useful. Great job, guys!
评论 #10022849 未加载
piratebroadcastalmost 10 years ago
So if somebody hacks isitvulnerable.com, they have a list of vulnerable rails sites.
评论 #10023631 未加载
brobinsonalmost 10 years ago
Great tool! Bookmarked.<p>Bug report: text here [1] is not rendering properly, but if I resize the window to be smaller it adjusts and is fine. Happens in Firefox 39.0.3 (no plugins) and Chrome 44.0.2403.130 (64-bit, no plugins) at 1000px window width on OSX Yosemite.<p>[1] <a href="http:&#x2F;&#x2F;i.imgur.com&#x2F;rgQqli8.png" rel="nofollow">http:&#x2F;&#x2F;i.imgur.com&#x2F;rgQqli8.png</a>
评论 #10023565 未加载
评论 #10023539 未加载
dboydalmost 10 years ago
Looks great. Your formatting on the result page is messed up in my browser (chrome on osx). You can see a screen shot here...<p><a href="https:&#x2F;&#x2F;annotate.driftt.com&#x2F;view?i=99nffsejxeiittq%2F2015-08-07_at_10.49_AM_(1).png%2F" rel="nofollow">https:&#x2F;&#x2F;annotate.driftt.com&#x2F;view?i=99nffsejxeiittq%2F2015-08...</a>
评论 #10023999 未加载
caioariedealmost 10 years ago
I&#x27;d like to know if there is something similar for Python, or something like <a href="https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;ruby-advisory-db" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;ruby-advisory-db</a> for Python.
评论 #10025124 未加载
busterarmalmost 10 years ago
THANK YOU!<p>I think this is really awesome...<p>...I have to go update a few projects right now.
thoughtpalettealmost 10 years ago
This is awesome, great idea! I see the sign-up for additional platforms. Thinking of supporting package.json and bower files?
评论 #10023133 未加载