
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
ybe-check
Advanced tools
Production-readiness security gatekeeper for vibe-coded apps — 16 scan modules, AI remediation, MCP server, VS Code extension, and bento dashboard.
Production-readiness security gatekeeper for vibe-coded apps.
16 scan modules · AI remediation · MCP server · VS Code + Copilot · Bento dashboard
pip install .
ybe-check init # Extension + MCP + Scan + Dashboard in one command
ybe-check scan . # Run all 16 modules
ybe-check report --severity high # Show high-severity findings
ybe-check dashboard # Launch bento grid dashboard
ybe-check setup # Install extension + configure MCP
python -m ybe_check.mcp_server # stdio transport
Tools: ybe.scan_repo · ybe.list_findings · ybe.get_remediation · ybe.get_security_context · ybe.enhance_prompt · ybe.get_fix_prompt · ybe.get_review_prompt
Prompts: security-audit · fix-critical · review-file
Auto-installs MCP on activation. Open Command Palette → "Ybe Check" to scan, audit, fix, and chat with Copilot.
ybe-check dashboard # http://127.0.0.1:7474
See A2K2/README.md for full documentation.
FAQs
Production-readiness security gatekeeper for vibe-coded apps — 16 scan modules, AI remediation, MCP server, VS Code extension, and bento dashboard.
The pypi package ybe-check receives a total of 20 weekly downloads. As such, ybe-check popularity was classified as not popular.
We found that ybe-check demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.