Capabilities

Ruby

Ruby package analysis and vulnerability scanning capabilities

Package analysis

Cataloger + EvidenceLicenseDependenciesPackage Manager Claims
DepthEdgesKindsFilesDigestsIntegrity Hash
ruby-gemfile-cataloger
Gemfile.lock
TransitiveRuntime, Dev
ruby-gemspec-cataloger
*.gemspec
DirectRuntime
ruby-installed-gemspec-cataloger
specifications/**/*.gemspec
TransitiveRuntime

Vulnerability scanning

Data SourceDisclosuresFixesTrack by
Source
Package
AffectedDateVersionsDate
GitHub Security Advisories (GHSA)
National Vulnerability Database (NVD)

Grype Configuration
Configuration KeyDescription
match.ruby.using-cpesUse CPE package identifiers to find vulnerabilities

Next steps

Last modified November 26, 2025: allow local too invocation (d20d613)