rails-security-audits

📁 shivamsinghchahar/rails-skills 📅 11 days ago
3
总安装量
3
周安装量
#58505
全站排名
安装命令
npx skills add https://github.com/shivamsinghchahar/rails-skills --skill rails-security-audits

Agent 安装分布

amp 3
github-copilot 3
codex 3
gemini-cli 3
cursor 3
opencode 3

Skill 文档

Rails Security Audits

Identify and fix security vulnerabilities in Rails applications. This skill covers vulnerability scanning, dependency auditing, and security best practices.

Quick Start

Add security gems:

group :development, :test do
  gem 'brakeman', require: false
  gem 'bundler-audit', require: false
end

Run security scans:

# Scan for Rails vulnerabilities
bundle exec brakeman

# Audit dependencies for known vulnerabilities
bundle exec bundler-audit check --update

# Update vulnerability database
bundle exec bundler-audit update

Setup security headers in Rails:

# config/initializers/content_security_policy.rb
Rails.application.configure do
  config.content_security_policy do |policy|
    policy.default_src :self
    policy.script_src :self, :unsafe_inline
    policy.style_src :self, :unsafe_inline
  end
end

Core Topics

Brakeman Security: See brakeman-security.md for static analysis and common vulnerabilities.

Bundler Audit: See bundler-audit.md for dependency vulnerability tracking.

Security Headers: See csp-headers.md for content security policy and headers.

Patterns: See patterns.md for common vulnerabilities and fixes.

Examples

See examples.md for configurations.