HTTP/2 200
date: Fri, 26 Dec 2025 11:05:28 GMT
content-type: text/html; charset=utf-8
server: cloudflare
last-modified: Thu, 25 Dec 2025 13:46:15 GMT
vary: Accept-Encoding
access-control-allow-origin: *
nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
expires: Fri, 26 Dec 2025 11:15:28 GMT
cache-control: max-age=14400
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=09fWIkYHhqOhcTbYqgfnpMYRoCs3tTmhQcqM1o%2BLlSf58Edo2ttpqP0eB2w67dyJE2uPEZLJhBCSjMGBt5A6BWG4sGrl1mw44mj%2FBvbg4r6SjIo%3D"}]}
x-proxy-cache: MISS
x-github-request-id: 2404:3E21CA:8DE585:9A1247:694E6BF8
cf-cache-status: MISS
content-encoding: gzip
cf-ray: 9b401a6dbfa93de5-BOM
alt-svc: h3=":443"; ma=86400
Brakeman: Brakeman Security Scanner
Secure Your Rails Applications
Brakeman is a free vulnerability scanner designed for Ruby on Rails applications. Statically analyze Rails application code to find security issues at any stage of development.
gem install brakeman
brakeman
== Brakeman Report ==
🎯
Rails-Specific
Built specifically for Ruby on Rails. Understands Rails patterns, conventions, and common vulnerability patterns.
🔧
Zero Configuration
Works out of the box with sensible defaults.
🔍
Broad Coverage
Detects SQL injection, cross-site scripting, command injection, and dozens of other vulnerability types.
Version 7.1.2
Brakeman 7.1.2 Released
December 2025 • Ruby 4.0 compatibility and fewer false positives
Dependency Updates
🎉 What's New
Update ruby_parser to remove max version restriction (Chedli Bourguiba )
Increase minimum Ruby version to 3.2.0
Reduce SQL injection false positives from count (and other) calls (#1936 )
Remove more XSS false positives related to Haml attribute builder
Read Full Release Notes →