Ross ROSS = Recommend OSS · open-source software intelligence for agents

rubysec/ruby-advisory-db resource

A database of vulnerable Ruby Gems observed · 2026-09-01

github.com/rubysec/ruby-advisory-db · homepage · Ruby · NOASSERTION (other) observed · 2026-09-01

Health v2 · maintenance only

77/100

  • Activity 100
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4950
  • days_rel: n/a
  • days_push: 2
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1070 stars · 248 forks observed · 2026-09-01

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A community-maintained database of security vulnerability advisories for Ruby gems and Ruby implementations, stored as YAML files identified by CVE or GHSA IDs. It serves as the data source for tools like bundler-audit that check Gemfile.lock files against known vulnerabilities.

Use cases

  • audit my Gemfile.lock for known gem vulnerabilities
  • find CVEs affecting a Ruby gem version
  • check if a Ruby implementation has security advisories
  • feed a vulnerability database into a Ruby dependency scanner
  • look up fixed versions for a gem CVE
  • contribute a new security advisory for a Ruby library

When to choose

  • you need canonical, plain-text advisory data for Ruby gems or rubies
  • you are building or using a Ruby dependency auditing tool like bundler-audit
  • you want a community-maintained, easily scriptable vulnerability dataset

When to avoid

  • you need advisories for non-Ruby ecosystems (use OSV, GitHub Advisory DB, or language-specific databases)
  • you want a ready-made scanning tool rather than raw data (use bundler-audit instead)
  • you need real-time automated vulnerability feeds with API access

Facets

dataset · maturity active

security vulnerability-scanning dependency-audit security developer-tools programming-languages ruby cli cross-platform rubygems advisory-database yaml cve ghsa bundler-audit supply-chain-security

2 sources

Member repositories

RepositoryRoleHealth v2
rubysec/ruby-advisory-dbmain77

For agents

markdown · JSON · MCP: product_card(name="rubysec/ruby-advisory-db")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem