Skip to content

Comment on Exploitation of an old Rails vulnerabilityparent

Comments

Thus, if you don't know what you're doing, subscribe to a service like Gem Canary (http://gemcanary.com/) so you get alerts.

We also have a mailing list we regularly send out updates to that we set up after the Rails vuln fiasco - you can sign up for it here, if interested: https://www.tinfoilsecurity.com/railscheck

I like this. Is there anything comparable for Python or Node.js?

Yes, try https://bundlescout.com/

Also http://getshrubbery.com/home which is free, but seemed mildly broken when I tried it (it seemed to forget some of my actually outdated packages when I tried it).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.