You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This week while doing research on two puma security advisories mentioned in Ruby Weekly, we learned about the concept of GHSA "repository‑level security advisories" (RLSA). The ruby-advisory-db project monitors GHSA database but we did not know about these advisories. Therefore they are not included in the "bundle audit" results.
Now that we do, we need the community's help to add to this list of security advisory sources. If anyone knows more about this topic, please add a comment to this issue, such as:
How to get a complete list of Ruby gems or "rubies" with RLSA's.
Add your project's RLSA.
Until we have established a more formal way to document this sources, I will continue to edit this description with more RLSA's.
GHSA - "repository‑level security advisories" (RLSA) list
LIST
NOTES