OSS TanbouSign in with GitHub

Check Gemfile.lock against the Ruby Advisory DB and fail CI on vulnerable gems or insecure sources

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
2,762
Primary language
Ruby
License
GPL-3.0
Repository last updated
Oct 2, 2026
On this page

Overview

bundler-audit is a security tool for Bundler projects. It compares Gemfile.lock against the Ruby Advisory DB, flags known vulnerable gem versions and insecure gem sources, and supports database updates, text/JSON/JUnit output, ignore configuration, and Rake integration. The current version is 0.9.3.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Compare locked gem versions with the Ruby Advisory DB

bundle-audit check --update updates the advisory database and scans the lockfile, reporting affected gems, advisory identifiers, criticality, and patched-version guidance. It also checks insecure gem sources.

Sources: [2]

Integrate JSON or JUnit output, ignores, custom lockfiles, and Rake tasks into CI

The CLI supports machine-readable formats, output files, alternate lockfiles, .bundler-audit.yml ignore lists, and Rake tasks for automated pipelines.

Sources: [2][4]

Best fit

Fits Ruby repositories that need a lightweight known-vulnerability gate for dependencies

It is easy to add to Rails and Ruby CI when teams want a lockfile-based dependency check. Version 0.9.3 adds official Bundler 4.x and Ruby 3.4, 3.5, and 4.0 support.

Sources: [4][2]

Before adoption

Coverage depends on advisory-database freshness and cannot prove an absence of vulnerabilities

Checks can run offline, but an outdated advisory database misses newly published issues. Ignore entries should have reasons and expiration, and bundler-audit should complement rather than replace SAST and OS/package scanning. The gem metadata declares Ruby 2.0+ and Bundler 1.2+.

Sources: [2][3][4]

Official sources

  1. [1]rubysec/bundler-audit — GitHub repository(2026-10-06)
  2. [2]bundler-audit — README(2026-10-06)
  3. [3]bundler-audit — gemspec metadata(2026-10-06)
  4. [4]bundler-audit — ChangeLog(2026-10-06)
  5. [5]bundler-audit — v0.9.3 release(2026-10-06)
Supplemental curator note

It is lightweight to adopt, but results depend on advisory database freshness and coverage. Update the database explicitly in CI, time-bound ignores, and combine it with other security scanners.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/rubysec/bundler-audit.git
  2. 2

    Enter the repository

    cd bundler-audit
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

2,762 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
9
Open PRs
24

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • bundler-audit
  • ruby-advisory-db
  • ruby
  • dependency-checker
  • patch-management
  • security
  • security-tools
  • security-audit
Stars
2,762
Forks
247
Watchers
41
Open issues
24
Contributors
63
Owner type
Organization
Primary language
Ruby
License
GPL-3.0
Repository last updated
Oct 2, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?