TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Show HN: Is it vulnerable? Drag-n-drop your Gemfile.lock to check

175 点作者 phillmv将近 10 年前

11 条评论

sciurus将近 10 年前
You can run this check yourself using the bundle-audit tool. It uses the list of vulnerabilities from ruby-advisory-db.<p>Checking the git history, I see that phillmv is a contributor to ruby-advisory-db.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;bundler-audit" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;bundler-audit</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;ruby-advisory-db" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;ruby-advisory-db</a>
评论 #10022993 未加载
phillmv将近 10 年前
Hey. We posted about our service last week and got great feedback. We took that feedback and decided to put isitvulnerable.com together to really showcase what you can get out of it &#x2F; uh check your dang Gemfile.lock at least.<p>We&#x27;re expanding platforms, so do tell us what to support next :).
评论 #10022807 未加载
评论 #10023236 未加载
评论 #10022964 未加载
评论 #10023485 未加载
评论 #10024893 未加载
评论 #10022906 未加载
Mojah将近 10 年前
If you&#x27;re into PHP, SensioLabs has a similar service you can use in your Composer.lock file: <a href="https:&#x2F;&#x2F;security.sensiolabs.org&#x2F;check" rel="nofollow">https:&#x2F;&#x2F;security.sensiolabs.org&#x2F;check</a><p>It&#x27;ll block any vulnerable version of a dependency in your project.
homakov将近 10 年前
Someone should reestimate severity of those &quot;CVEs&quot;. I got 10 warnings and none of them is any severe for my app(and yours too, likely), so I&#x27;m definitely not vulnerable.<p>Also LOL &quot;CSRF Vulnerability in jquery-rails&quot; is known as not a bug at all.
评论 #10024781 未加载
bshimmin将近 10 年前
This is terrific. Easy to understand, fast, and very useful. Great job, guys!
评论 #10022849 未加载
piratebroadcast将近 10 年前
So if somebody hacks isitvulnerable.com, they have a list of vulnerable rails sites.
评论 #10023631 未加载
brobinson将近 10 年前
Great tool! Bookmarked.<p>Bug report: text here [1] is not rendering properly, but if I resize the window to be smaller it adjusts and is fine. Happens in Firefox 39.0.3 (no plugins) and Chrome 44.0.2403.130 (64-bit, no plugins) at 1000px window width on OSX Yosemite.<p>[1] <a href="http:&#x2F;&#x2F;i.imgur.com&#x2F;rgQqli8.png" rel="nofollow">http:&#x2F;&#x2F;i.imgur.com&#x2F;rgQqli8.png</a>
评论 #10023565 未加载
评论 #10023539 未加载
dboyd将近 10 年前
Looks great. Your formatting on the result page is messed up in my browser (chrome on osx). You can see a screen shot here...<p><a href="https:&#x2F;&#x2F;annotate.driftt.com&#x2F;view?i=99nffsejxeiittq%2F2015-08-07_at_10.49_AM_(1).png%2F" rel="nofollow">https:&#x2F;&#x2F;annotate.driftt.com&#x2F;view?i=99nffsejxeiittq%2F2015-08...</a>
评论 #10023999 未加载
caioariede将近 10 年前
I&#x27;d like to know if there is something similar for Python, or something like <a href="https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;ruby-advisory-db" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rubysec&#x2F;ruby-advisory-db</a> for Python.
评论 #10025124 未加载
busterarm将近 10 年前
THANK YOU!<p>I think this is really awesome...<p>...I have to go update a few projects right now.
thoughtpalette将近 10 年前
This is awesome, great idea! I see the sign-up for additional platforms. Thinking of supporting package.json and bower files?
评论 #10023133 未加载