On this page
Overview
bundler-audit is a security tool for Bundler projects. It compares Gemfile.lock against the Ruby Advisory DB, flags known vulnerable gem versions and insecure gem sources, and supports database updates, text/JSON/JUnit output, ignore configuration, and Rake integration. The current version is 0.9.3.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Compare locked gem versions with the Ruby Advisory DB
bundle-audit check --update updates the advisory database and scans the lockfile, reporting affected gems, advisory identifiers, criticality, and patched-version guidance. It also checks insecure gem sources.
Sources: [2]
Best fit
Before adoption
Coverage depends on advisory-database freshness and cannot prove an absence of vulnerabilities
Checks can run offline, but an outdated advisory database misses newly published issues. Ignore entries should have reasons and expiration, and bundler-audit should complement rather than replace SAST and OS/package scanning. The gem metadata declares Ruby 2.0+ and Bundler 1.2+.
Official sources
- [1]rubysec/bundler-audit — GitHub repository(2026-10-06)
- [2]bundler-audit — README(2026-10-06)
- [3]bundler-audit — gemspec metadata(2026-10-06)
- [4]bundler-audit — ChangeLog(2026-10-06)
- [5]bundler-audit — v0.9.3 release(2026-10-06)
Supplemental curator note
It is lightweight to adopt, but results depend on advisory database freshness and coverage. Update the database explicitly in CI, time-bound ignores, and combine it with other security scanners.
Try it in 3 steps
- 1
Get the source
git clone --depth 1 https://github.com/rubysec/bundler-audit.git - 2
Enter the repository
cd bundler-audit - 3
Check the official steps
Continue with the commands in the README Installation, Quick Start, or Getting Started section.
find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Growth
Growth trends · Last 30 days
2,762 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 9
- Open PRs
- 24
Development activity is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- bundler-audit
- ruby-advisory-db
- ruby
- dependency-checker
- patch-management
- security
- security-tools
- security-audit
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Kamal14,633 Stars
2 shared tag(s) · 1 shared category(s) · Same language
deploy Dockerized web apps to bare metal or cloud VMs over SSH and switch traffic with kamal-proxy for zero-downtime releases
Ruby - CarrierWave8,768 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Handle Ruby web-app file uploads with cache/store separation, processing, and ORM-mounted uploaders
Ruby - Openlane319 Stars
2 shared tag(s) · 1 shared category(s)
an open-source GRC automation server connecting controls, evidence, people, vendors, and risks across compliance frameworks
Go - Devise24,356 Stars
2 shared tag(s) · Same language
compose Rails authentication workflows from modular features on top of Warden
Ruby - Fluentd13,598 Stars
2 shared tag(s) · Same language
Connect sources, filters, buffers, and outputs through plugins in one log and event-delivery pipeline
Ruby - mkcert59,718 Stars
1 shared tag(s) · 2 shared category(s)
create a local CA and easily issue browser-trusted TLS certificates for localhost and development domains
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.