0.6.2 / 2019-04-09
- Add:
--format=default|plain|junit
- Fix: Escape XML output for junit formatter
0.6.1 / 2019-01-17
- Require bundler
>= 1.2.0, < 3 to support bundler 2.0.
0.6.0 / 2017-07-18
- Added
--quiet option to check and update commands (@jaredbeck).
- Added
bin/bundler-audit which will be executed when bundle audit is ran
(@vassilevsky).
0.5.0 / 2016-02-28
CLI
- Added the
--update option to bundle-audit check.
bundle-audit update now returns a non-zero exit status on error.
bundle-audit update only updates ~/.local/share/ruby-advisory-db, if it is a git
repository.
0.4.0 / 2015-06-30
- Require ruby >= 1.9.3 due to i18n gem deprecating < 1.9.3.
- Added Bundler::Audit::Advisory#osvdb.
- Resolve the IP addresses of gem sources and ignore intranet gem sources.
(PR #90)
- Use ISO8601 date format when querying the git timestamp of ruby-advisory-db.
(PR #92)
CLI
- Print the CVE or OSVDB id.
- No longer print "Unpatched versions found!" when an insecure gem source
is detected. (PR #84)
0.3.1 / 2014-04-20
- Added thor ~> 0.18 as a dependency.
- No longer rely on the vendored version of thor within bundler.
- Store the timestamp of when
data/ruby-advisory-db was last updated in
data/ruby-advisory-db.ts.
- Use
data/ruby-advisory-db.ts instead of the creation time of the
dataruby-advisory-db directory, which is always the install time
of the rubygem.
0.3.0 / 2013-10-31
CLI
- Added the
bundle-audit update sub-command.
0.2.0 / 2013-03-05
0.1.2 / 2013-02-17
CLI
- Simply parse the
Gemfile.lock instead of loading the bundle (@grosser).
- Exit with non-zero status on failure (@grosser).
0.1.1 / 2013-02-12
- Fixed a Ruby 1.8 syntax error.
Advisories
CLI
- If the advisory has no
patched_versions, recommend removing or disabling
the gem until a patch is made available.
0.1.0 / 2013-02-11
- Initial release:
- Checks for vulnerable versions of gems in
Gemfile.lock.
- Prints advisory information.
- Does not require a network connection.
Advisories