Ruby

Ruby package analysis and vulnerability scanning capabilities

Package analysis

Cataloger + Evidence License Dependencies Package Manager Claims
Depth Edges Kinds Files Digests Integrity Hash
ruby-gemfile-cataloger
Gemfile.lock
transitive runtime, dev
ruby-gemspec-cataloger
*.gemspec
direct runtime
ruby-installed-gemspec-cataloger
specifications/**/*.gemspec
transitive runtime

Vulnerability scanning

Data Source Disclosures Fixes Track by
Source
Package
Affected Date Versions Date
GitHub Security Advisories (GHSA)
National Vulnerability Database (NVD)
Grype Configuration
Configuration Key Description
match.ruby.using-cpes Use CPE package identifiers to find vulnerabilities

Next steps

Last modified October 23, 2025: fix section ref (9417a27)