Kargo automates promotion across dev, staging, and prod with approval gates and verification. Open source, built by the team behind Argo CD. Download now. Learn more →
Top 23 Ruby Security Projects
-
Project mention: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone | news.ycombinator.com | 2026-08-03
Are you referring to GitHub policies? I haven’t seen issues like that from people publishing security tools before.
Metasploit is one example: https://github.com/rapid7/metasploit-framework
-
AppSignal
AppSignal knows why the f*#k it crashed. Stop vibe-debugging. Every exception, every backtrace, grouped so you see patterns, not noise.
-
wpscan
WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com
-
I use: https://brakemanscanner.org/, https://github.com/gitleaks/gitleaks, https://github.com/zizmorcore/zizmor/
-
-
-
WebHackersWeapons
⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting
-
-
Kargo
Stop Scripting Promotions. Start Shipping with Kargo. Kargo automates promotion across dev, staging, and prod with approval gates and verification. Open source, built by the team behind Argo CD. Download now.
-
PasswordPusher
🔐 Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.
-
-
Project mention: A Typosquatted Gem Almost Shipped, Caught by Luck: A Ruby Supply Chain Security Playbook | dev.to | 2026-08-11
A checklist people can forget is a suggestion; a CI gate is a rule. Two independent scanners catch different things, and layering them is cheap: bundler-audit (checking Gemfile.lock against the ruby-advisory-db) and Google's OSV-Scanner (fed by osv.dev). It runs on every dependency-touching PR and weekly on a schedule:
-
OAuth2
🔐 oauth2 - A Ruby wrapper for the OAuth 2.0, & 2.1 Authorization Frameworks, including OpenID Connect (OIDC) (by ruby-oauth)
oauth2 v2.0.18 was released... almost five months ago. And I never got around to posting about it. Being unemployed is a LOT of work...
-
-
-
-
rails-security-checklist
:key: Community-driven Rails Security Checklist (see our GitHub Issues for the newest checks that aren't yet in the README)
-
best-practices-badge
🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
Project mention: Kubernetes earned its security badge in 2017 and never came back | dev.to | 2026-07-31bestpractices.dev has been running for a decade, the CNCF requires it before a project can graduate, and it had never crossed my desk. So I went and read it properly: the criteria, the Rails app behind it, and the daily statistics it has been publishing at a public URL the whole time. This is what I found, including the part the program's own maintainer raised in 2024 and nobody has fixed.
-
-
MobileHackersWeapons
Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting
-
-
-
Hashids
A small Ruby gem to generate YouTube-like hashes from one or many numbers. Use hashids when you do not want to expose your database ids to the user.
-
-
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
Ruby Security discussion
Ruby Security related posts
-
Creepy Crawlies
-
Tooling every AI software harness should have
-
A Typosquatted Gem Almost Shipped, Caught by Luck: A Ruby Supply Chain Security Playbook
-
Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
-
Ronin – A Security Toolkit
-
WPScan: WordPress Security Scanner
-
How to integrate Brakeman Security Scanner with GitHub Code Scanning
-
A note from our sponsor - Kargo
akuity.io | 11 Sep 2026
Index
What are some of the best open-source Security projects in Ruby? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | Metasploit | 38,950 |
| 2 | wpscan | 9,762 |
| 3 | Brakeman | 7,268 |
| 4 | WhatWeb | 6,819 |
| 5 | Rack::Attack | 5,760 |
| 6 | WebHackersWeapons | 5,054 |
| 7 | SecureHeaders | 3,226 |
| 8 | PasswordPusher | 3,186 |
| 9 | inspec | 3,087 |
| 10 | bundler-audit | 2,757 |
| 11 | OAuth2 | 2,179 |
| 12 | authentication-zero | 1,874 |
| 13 | cocoapods-keys | 1,548 |
| 14 | username-anarchy | 1,409 |
| 15 | rails-security-checklist | 1,363 |
| 16 | best-practices-badge | 1,358 |
| 17 | cfn_nag | 1,307 |
| 18 | MobileHackersWeapons | 1,279 |
| 19 | invisible_captcha | 1,250 |
| 20 | haiti | 1,000 |
| 21 | Hashids | 985 |
| 22 | RbNaCl | 985 |
| 23 | linux-baseline | 874 |