Skip to content

GHSA/RLSA - "repository‑level security advisories" list #1107

@jasnow

Description

@jasnow

GHSA - "repository‑level security advisories" (RLSA) list

LIST

NOTES

  1. This week while doing research on two puma security advisories mentioned in Ruby Weekly, we learned about the concept of GHSA "repository‑level security advisories" (RLSA). The ruby-advisory-db project monitors GHSA database but we did not know about these advisories. Therefore they are not included in the "bundle audit" results.
  2. Now that we do, we need the community's help to add to this list of security advisory sources. If anyone knows more about this topic, please add a comment to this issue, such as:
    • How to get a complete list of Ruby gems or "rubies" with RLSA's.
    • Add your project's RLSA.
  3. Until we have established a more formal way to document this sources, I will continue to edit this description with more RLSA's.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions