When a new gem is added to our Gemfile
or when versions are changed in Gemfile.lock
, we ask developers to reach out to the AppSec team to request a review. As an AppSec engineer performing the review, please follow the steps mentioned below to perform reviews like these:
diffgem
helper function in gitlab-com/gl-security/appsec/tooling/appsec-command-line-utils was created to assist in reviewing gem version changes by showing only the diff
s for Ruby files. (excluding changes to specs, json
, yaml
, and other noise)After you have done the above, please add a comment to the MR/issue the developer pinged us on mentioning that: