rubygems
rails
1 versiondiscovered · its AI-security audit & verification record by name.
8.0.1unauditedresolved-commitattested-tag
coverage →rails/rails @ 89012345678901ab…
Release tag repointed on 2026-08-16: this version's mapping moved from 890123456789… to ab1234567890…. Prior coverage applied to the old commit and does not follow silently — see trust incidents.
AI security assessmentcleanqwen2.5-7b-instruct
Sampled framework surface applies parameter filtering and escaping consistently.
Methodology
Sources @ 8901234567
README.md, actionpack/lib/action_controller/metal/strong_parameters.rb, activerecord/lib/active_record/sanitization.rb, actionview/lib/action_view/helpers/sanitize_helper.rb, activesupport/lib/active_support/message_verifier.rb, railties/lib/rails/application.rb
Parts 6 files, 13800 bytes
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local
No signed audits for this version yet. It is a candidate for the audit queue.
Gate this package in CI
Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.
signet gate --purl pkg:gem/rails@8.0.1 --registry https://signet.seekerslab.com
README badge
Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.
