TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Rails Vulnerability Compilation

46 点作者 ainsleyb大约 12 年前

3 条评论

phillmv大约 12 年前
Hi, I'm with <a href="http://rubysec.github.com/" rel="nofollow">http://rubysec.github.com/</a><p>We maintain a freely available advisory database <a href="https://github.com/rubysec/ruby-advisory-db/" rel="nofollow">https://github.com/rubysec/ruby-advisory-db/</a> designed to be easily machine readable.<p>We also maintain a free ruby-wide security announcement mailing list: <a href="https://groups.google.com/forum/?fromgroups#!forum/rubysec-announce" rel="nofollow">https://groups.google.com/forum/?fromgroups#!forum/rubysec-a...</a><p>The rubysec-advisory-db is meant to power discovery tools such as <a href="https://github.com/postmodern/bundler-audit" rel="nofollow">https://github.com/postmodern/bundler-audit</a> (from which it was originally extracted) or <a href="https://gemcanary.com" rel="nofollow">https://gemcanary.com</a> (it bears mentioning that my company made it). I'm pretty sure it will be used in codeclimate's upcoming security monitor <a href="https://codeclimate.com/security-monitor" rel="nofollow">https://codeclimate.com/security-monitor</a> given that Bryan is a regular contributor.<p>If you're interested in security, please consider checking us out. Most of rubysec is composed of security professionals, and we're all interested in improving the ecosystem-at-large. Submit issues against the advisory or simply fork it <a href="https://github.com/rubysec/ruby-advisory-db/" rel="nofollow">https://github.com/rubysec/ruby-advisory-db/</a><p>Regards and apologies for slightly hijacking the thread.
评论 #5397832 未加载
评论 #5398379 未加载
Bjoern大约 12 年前
Its quite interesting that even customers start asking now "oh its rails, that is so insecure". Sign, quite alot of media hysteria going on.
jorgenev大约 12 年前
This was a good write up.