A curated list of awesome Ruby Security related resources.
List inspired by the awesome list thing.
Web Framework Hardening
- secure-headers - Manages application of security headers with many safe defaults
- hawkeye - Multi purpose security/vulnerability/risk scanning tool supporting Ruby, Node.js, Python, PHP and Java.
- Salus - Multi purpose security scanning tool supporting Ruby, Node, Python and Go.
Static Code Analysis
- brakeman - A static analysis security vulnerability scanner for Ruby on Rails applications.
- rubocop-gitlab-security - A set of rules to extend rubocop with additional security rules.
- dawnscanner - A static analysis security scanner for ruby applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.
- git-secrets - Prevents you from committing secrets and credentials into git repositories.
- DevSkim - DevSkim is a set of IDE plugins and rules that provide security "linting" capabilities. Also has support for CLI so it can be integrated into CI/CD pipeline.
- ban-sensitive-files - Checks filenames to be committed against a library of filename rules to prevent storing sensitive files in Git. Checks some files for sensitive contents (for example authToken inside .npmrc file).
Vulnerabilities and Security Advisories
- bundler-audit - Patch-level verification for Ruby apps.
- RailsGoat - A vulnerable version of Rails that follows the OWASP Top 10 http://railsgoat.cktricky.com .
- DeleteMe - Educational insecure Rails application.
Articles & Guides
- Rails Security Guides - The essentials to read when dealing with Rails Applications.
- Securing Ruby and Rails Apps - Applying static code analysis and dependency checking in your CI/CD pipeline.
- OWASP Ruby on Rails Cheatsheet - This Cheatsheet intends to provide quick basic Ruby on Rails security tips for developers. It complements, augments or emphasizes points brought up in the rails security guide from rails core.
- Rails security checklist -
🔑Community-driven Rails Security Checklist.
- Ruby Bug Bounty Program - Found a bug in the Ruby language? Report it there.
- Ruby Security Updates - Follow the latest security announcements.
Found an awesome project, package, article, other type of resources related to Ruby Security? Send me a pull request! Just follow the guidelines. Thank you!
say hi on Twitter