From 2b4e01c67e30e33c96c4c8e80c224a41cae53ff5 Mon Sep 17 00:00:00 2001 From: stacksharebot Date: Tue, 5 Mar 2024 16:35:39 +0000 Subject: [PATCH 1/4] Create techstack.yml --- techstack.yml | 304 ++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 304 insertions(+) create mode 100644 techstack.yml diff --git a/techstack.yml b/techstack.yml new file mode 100644 index 0000000..26368f3 --- /dev/null +++ b/techstack.yml @@ -0,0 +1,304 @@ +repo_name: yonasb/railStrap +report_id: acecc98a621d23ec81e095b39472f913 +version: 0.1 +repo_type: Public +timestamp: '2024-03-05T16:35:38+00:00' +requested_by: hugodias +provider: github +branch: master +detected_tools_count: 17 +tools: +- name: CSS 3 + description: The latest evolution of the Cascading Style Sheets language + website_url: https://developer.mozilla.org/en-US/docs/Web/CSS/CSS3 + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Languages + image_url: https://img.stackshare.io/service/6727/css.png + detection_source_url: https://github.com/yonasb/railStrap + detection_source: Repo Metadata +- name: JavaScript + description: Lightweight, interpreted, object-oriented language with first-class + functions + website_url: https://developer.mozilla.org/en-US/docs/Web/JavaScript + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Languages + image_url: https://img.stackshare.io/service/1209/javascript.jpeg + detection_source_url: https://github.com/yonasb/railStrap + detection_source: Repo Metadata +- name: Ruby + description: A dynamic, interpreted, open source programming language with a focus + on simplicity and productivity + website_url: https://www.ruby-lang.org + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Languages + image_url: https://img.stackshare.io/service/989/ruby.png + detection_source_url: https://github.com/yonasb/railStrap + detection_source: Repo Metadata +- name: Rails + description: Web development that doesn't hurt + website_url: http://rubyonrails.org/ + version: 3.2.6 + license: MIT + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Frameworks (Full Stack) + image_url: https://img.stackshare.io/service/990/x57_Lorv.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile.lock + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z +- name: jQuery + description: The Write Less, Do More, JavaScript Library. + website_url: http://jquery.com/ + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: Javascript UI Libraries + image_url: https://img.stackshare.io/service/1021/lxEKmMnB_400x400.jpg + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z +- name: SQLite + description: A software library that implements a self-contained, serverless, zero-configuration, + transactional SQL database engine + website_url: http://www.sqlite.org/ + open_source: false + hosted_saas: true + category: Data Stores + sub_category: Databases + image_url: https://img.stackshare.io/service/1071/sqlite.jpg + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 10:59:03.000000000 Z +- name: Git + description: Fast, scalable, distributed revision control system + website_url: http://git-scm.com/ + open_source: true + hosted_saas: false + category: Build, Test, Deploy + sub_category: Version Control System + image_url: https://img.stackshare.io/service/1046/git.png + detection_source_url: https://github.com/yonasb/railStrap + detection_source: Repo Metadata +- name: RubyGems + description: Easily download, install, and use ruby software packages on your system + website_url: https://rubygems.org/ + open_source: false + hosted_saas: false + category: Build, Test, Deploy + sub_category: Package Managers + image_url: https://img.stackshare.io/service/12795/5jL6-BA5_400x400.jpeg + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z +- name: Twilio SendGrid + description: Email Delivery. Simplified. + website_url: http://sendgrid.com + open_source: false + hosted_saas: true + category: Communications + sub_category: Transactional Email + image_url: https://img.stackshare.io/service/43/kQ_6nwmP.jpg + detection_source_url: https://github.com/yonasb/railStrap/blob/master/config/environments/production.rb + detection_source: config/environments/production.rb + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z +- name: UglifyJS + description: A JavaScript parser, minifier, compressor and beautifier toolkit. + website_url: http://lisperator.net/uglifyjs/ + open_source: true + hosted_saas: false + category: Libraries + sub_category: Javascript Utilities & Libraries + image_url: https://img.stackshare.io/service/2203/default_9058af6f02375a99f634f537d727e32df92ac262.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z +- name: bcrypt-ruby + description: Bcrypt + package_url: https://rubygems.org/bcrypt-ruby + version: 3.0.1 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: RubyGems Packages + image_url: https://img.stackshare.io/package/19102/default_ca845424a738bd71840d7357a8f789db0cee794d.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile.lock + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z +- name: coffee-rails + description: CoffeeScript adapter for the Rails asset pipeline + package_url: https://rubygems.org/coffee-rails + version: 3.2.2 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: RubyGems Packages + image_url: https://img.stackshare.io/package/18896/default_9386886dd1c6c396a11bd4b49732afb9ec444f8d.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile.lock + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z +- name: jquery-rails + description: This gem provides jQuery and the jQuery-ujs driver for your Rails 4+ + application + package_url: https://rubygems.org/jquery-rails + version: 2.0.2 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: RubyGems Packages + image_url: https://img.stackshare.io/package/18864/default_96cb61a9c0f8ef41b80df83209dca4f4c229184e.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile.lock + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z + vulnerabilities: + - name: 'Duplicate Advisory: Prototype Pollution in jquery' + cve_id: CVE-2019-5428 + cve_url: https://github.com/advisories/GHSA-wv67-q8rr-grjp + detected_date: Sep 26 + severity: moderate + first_patched: 3.4.0 + - name: jquery-rails and jquery-ujs subject to Exposure of Sensitive Information + cve_id: CVE-2015-1840 + cve_url: https://github.com/advisories/GHSA-4whc-pp4x-9pf3 + detected_date: Aug 22 + severity: moderate + first_patched: 3.1.3 + - name: jQuery Cross Site Scripting vulnerability + cve_id: CVE-2020-23064 + cve_url: https://github.com/advisories/GHSA-257q-pv89-v3xv + detected_date: Jul 8 + severity: moderate + first_patched: 4.4.0 + - name: Cross-Site Scripting in jquery + cve_id: CVE-2020-7656 + cve_url: https://github.com/advisories/GHSA-q4m3-2j7h-f7xw + detected_date: Jul 6 + severity: moderate + first_patched: 2.2.0 + - name: Cross-Site Scripting (XSS) in jquery + cve_id: CVE-2015-9251 + cve_url: https://github.com/advisories/GHSA-rmxg-73gg-4p98 + detected_date: Jul 6 + severity: moderate + first_patched: 4.2.0 + - name: Cross-Site Scripting in jquery + cve_id: CVE-2012-6708 + cve_url: https://github.com/advisories/GHSA-2pqj-h3vj-pqgw + detected_date: Jul 6 + severity: moderate + first_patched: 2.2.0 + - name: XSS in jQuery as used in Drupal, Backdrop CMS, and other products + cve_id: CVE-2019-11358 + cve_url: https://github.com/advisories/GHSA-6c3j-c64m-qhgq + detected_date: May 31 + severity: moderate + first_patched: 4.3.4 + - name: Potential XSS vulnerability in jQuery + cve_id: CVE-2020-11022 + cve_url: https://github.com/advisories/GHSA-gxr4-xjj5-5px2 + detected_date: Sep 26 + severity: moderate + first_patched: 4.4.0 + - name: Potential XSS vulnerability in jQuery + cve_id: CVE-2020-11023 + cve_url: https://github.com/advisories/GHSA-jpcq-cgw6-v4j6 + detected_date: May 5 + severity: moderate + first_patched: 4.4.0 +- name: json + description: This is a JSON implementation as a Ruby extension in C + package_url: https://rubygems.org/json + version: 1.7.3 + license: Ruby + open_source: true + hosted_saas: false + category: Libraries + sub_category: RubyGems Packages + image_url: https://img.stackshare.io/package/18822/default_19184669508c0f71aec9521d5f14d71b77203130.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile.lock + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z + vulnerabilities: + - name: Unsafe object creation in json RubyGem + cve_id: CVE-2020-10663 + cve_url: https://github.com/advisories/GHSA-jphg-qwrw-7w9g + detected_date: Aug 22 + severity: high + first_patched: 2.3.0 + - name: JSON gem has Improper Input Validation vulnerability + cve_id: CVE-2013-0269 + cve_url: https://github.com/advisories/GHSA-x457-cw4h-hq5f + detected_date: Aug 22 + severity: high + first_patched: 1.7.7 +- name: sass-rails + description: Sass adapter for the Rails asset pipeline + package_url: https://rubygems.org/sass-rails + version: 3.2.5 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: RubyGems Packages + image_url: https://img.stackshare.io/package/18876/default_d416e715a80ce80ae31b87cff032f5873c8a9d2a.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile.lock + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z +- name: sqlite3 + description: This module allows Ruby programs to interface with the SQLite3 database + engine + package_url: https://rubygems.org/sqlite3 + version: 1.3.6 + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: RubyGems Packages + image_url: https://img.stackshare.io/package/18820/default_6564ae059af6c4ea7065fd2329370c7a05341cf8.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile.lock + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 22:42:27.000000000 Z +- name: uglifier + description: Uglifier minifies JavaScript files by wrapping UglifyJS to be accessible + in Ruby + package_url: https://rubygems.org/uglifier + version: 1.2.4 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: RubyGems Packages + image_url: https://img.stackshare.io/package/18967/default_20d16c1471b93397c8ef93b19baf0989f59663c0.png + detection_source_url: https://github.com/yonasb/railStrap/blob/master/Gemfile.lock + detection_source: Gemfile + last_updated_by: Hugo Dias + last_updated_on: 2012-06-16 14:25:07.000000000 Z + vulnerabilities: + - name: Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js + cve_id: CVE-2015-8857 + cve_url: https://github.com/advisories/GHSA-34r7-q49f-h37c + detected_date: Mar 28 + severity: critical + first_patched: 2.7.2 From c6777ed2e397fa396750d817287947a9f6bcda09 Mon Sep 17 00:00:00 2001 From: stacksharebot Date: Tue, 5 Mar 2024 16:35:40 +0000 Subject: [PATCH 2/4] Create techstack.md --- techstack.md | 171 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 171 insertions(+) create mode 100644 techstack.md diff --git a/techstack.md b/techstack.md new file mode 100644 index 0000000..354708c --- /dev/null +++ b/techstack.md @@ -0,0 +1,171 @@ + +
+ +# Tech Stack File +![](https://img.stackshare.io/repo.svg "repo") [yonasb/railStrap](https://github.com/yonasb/railStrap)![](https://img.stackshare.io/public_badge.svg "public") +

+|17
Tools used|03/05/24
Report generated| +|------|------| +
+ +## Languages (3) + + + + + + + + +
+ CSS 3 +
+ CSS 3 +
+ +
+ JavaScript +
+ JavaScript +
+ +
+ Ruby +
+ Ruby +
+ +
+ +## Frameworks (2) + + + + + + +
+ Rails +
+ Rails +
+ v3.2.6 +
+ jQuery +
+ jQuery +
+ +
+ +## Data (1) + + + + +
+ SQLite +
+ SQLite +
+ +
+ +## DevOps (2) + + + + + + +
+ Git +
+ Git +
+ +
+ RubyGems +
+ RubyGems +
+ +
+ +## Software as a Service (SaaS) (1) + + + + +
+ Twilio SendGrid +
+ Twilio SendGrid +
+ +
+ +## Other (1) + + + + +
+ UglifyJS +
+ UglifyJS +
+ +
+ + +## Open source packages (7) + +## RubyGems (7) + +|NAME|VERSION|LAST UPDATED|LAST UPDATED BY|LICENSE|VULNERABILITIES| +|:------|:------|:------|:------|:------|:------| +|[bcrypt-ruby](https://rubygems.org/bcrypt-ruby)|v3.0.1|06/16/12|Hugo Dias |MIT|N/A| +|[coffee-rails](https://rubygems.org/coffee-rails)|v3.2.2|06/16/12|Hugo Dias |MIT|N/A| +|[jquery-rails](https://rubygems.org/jquery-rails)|v2.0.2|06/16/12|Hugo Dias |MIT|[CVE-2019-5428](https://github.com/advisories/GHSA-wv67-q8rr-grjp) (Moderate)
[CVE-2015-1840](https://github.com/advisories/GHSA-4whc-pp4x-9pf3) (Moderate)
[CVE-2020-23064](https://github.com/advisories/GHSA-257q-pv89-v3xv) (Moderate)
[CVE-2020-7656](https://github.com/advisories/GHSA-q4m3-2j7h-f7xw) (Moderate)
[CVE-2015-9251](https://github.com/advisories/GHSA-rmxg-73gg-4p98) (Moderate)
[CVE-2012-6708](https://github.com/advisories/GHSA-2pqj-h3vj-pqgw) (Moderate)
[CVE-2019-11358](https://github.com/advisories/GHSA-6c3j-c64m-qhgq) (Moderate)
[CVE-2020-11022](https://github.com/advisories/GHSA-gxr4-xjj5-5px2) (Moderate)
[CVE-2020-11023](https://github.com/advisories/GHSA-jpcq-cgw6-v4j6) (Moderate)| +|[json](https://rubygems.org/json)|v1.7.3|06/16/12|Hugo Dias |Ruby|[CVE-2020-10663](https://github.com/advisories/GHSA-jphg-qwrw-7w9g) (High)
[CVE-2013-0269](https://github.com/advisories/GHSA-x457-cw4h-hq5f) (High)| +|[sass-rails](https://rubygems.org/sass-rails)|v3.2.5|06/16/12|Hugo Dias |MIT|N/A| +|[sqlite3](https://rubygems.org/sqlite3)|v1.3.6|06/16/12|Hugo Dias |BSD-3-Clause|N/A| +|[uglifier](https://rubygems.org/uglifier)|v1.2.4|06/16/12|Hugo Dias |MIT|[CVE-2015-8857](https://github.com/advisories/GHSA-34r7-q49f-h37c) (Critical)| + +
+
+ +Generated via [Stack File](https://github.com/marketplace/stack-file) From 5f376e1c29b8106901e923c30ee748c120d382b5 Mon Sep 17 00:00:00 2001 From: stacksharebot Date: Wed, 13 Mar 2024 16:31:04 +0000 Subject: [PATCH 3/4] Update techstack.yml --- techstack.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/techstack.yml b/techstack.yml index 26368f3..b8773d6 100644 --- a/techstack.yml +++ b/techstack.yml @@ -2,7 +2,7 @@ repo_name: yonasb/railStrap report_id: acecc98a621d23ec81e095b39472f913 version: 0.1 repo_type: Public -timestamp: '2024-03-05T16:35:38+00:00' +timestamp: '2024-03-13T16:31:03+00:00' requested_by: hugodias provider: github branch: master From 1f370c19062d2a5020a2d3b571b4639f76705696 Mon Sep 17 00:00:00 2001 From: stacksharebot Date: Wed, 13 Mar 2024 16:31:05 +0000 Subject: [PATCH 4/4] Update techstack.md --- techstack.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/techstack.md b/techstack.md index 354708c..a3bd21b 100644 --- a/techstack.md +++ b/techstack.md @@ -36,7 +36,7 @@ Full tech stack [here](/techstack.md) # Tech Stack File ![](https://img.stackshare.io/repo.svg "repo") [yonasb/railStrap](https://github.com/yonasb/railStrap)![](https://img.stackshare.io/public_badge.svg "public")

-|17
Tools used|03/05/24
Report generated| +|17
Tools used|03/13/24
Report generated| |------|------|