Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

bundler-audit-fix

Package Overview
Dependencies
Maintainers
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

bundler-audit-fix

  • 0.3.0
  • Rubygems
  • Socket score

Version published
Maintainers
1
Created
Source

Bundler::Audit::Fix

Gem Version

Automatically apply patched version of gems audited by rubysec/bunder-audit.

Installation

Add this line to your application's Gemfile:

gem 'bundler-audit-fix'

And then execute:

$ bundle install

Or install it yourself as:

$ gem install bundler-audit-fix

Usage

$ bundle-audit-fix update [dir]

.bundler-audit.yml

In addition to the original configuration, it supports replacement block. If a gem that is related to a fixed and same version and not directly listed in the Gemfile (e.g. Rails family) needs to be updated, bundle-audit-fix will replace according to the specified like below.

replacement:
  rails:
    - actionpack
    - actionview
    - activemodel
    - activerecord
    - actionmailer
    - activejob
    - actioncable
    - activestorage
    - activesupport
    - actionmailbox
    - actiontext
    - railties

Contributing

Bug reports and pull requests are welcome on GitHub at https://github.com/nobuyo/bundler-audit-fix.

License

Copyright (c) 2021 Nobuo Takizawa

bundler-audit-fix is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

bundler-audit-fix is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with bundler-audit-fix. If not, see https://www.gnu.org/licenses/.

FAQs

Package last updated on 18 Apr 2022

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc