brakeman · Issues· 120 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #2046
False positive: `HAML::AttributeBuilder.build_class` incorrectly flagged as XSS
Updated Sep 9, 2026 - #2045
request: strong params checks for id (key) columns
Updated Sep 4, 2026 - #2043
Unscoped Find should exclude only if all belongs_to associations are optional
Updated Aug 30, 2026 - #2042
Parallelise index_call_sites and process_libs: ~75% of scan time is single-threaded on large apps
Updated Aug 24, 2026 - #1558
Poor performance processing repeated conditional reassignments
Updated Aug 23, 2026 - #2041
False Positive: Regexp containing an escaped $ is marked unsafe
Updated Aug 21, 2026 - #2040
Add warnings for dangerous content security policy settings autogenerated by Rails
Updated Aug 20, 2026 - #2020
Support reading config from ignore file
Updated Apr 23, 2026 - #2018
Hash lookup on frozen constant should untaint the result
Updated Apr 19, 2026 - #1816
UnsafeReflection requires array to be defined with values strictly in the context of the execution
Updated Jan 29, 2026 - #1992
How to write reports to file and summary to stdout?
Updated Jan 22, 2026 - #1956
[Format Error] on code field with Prism parser- Brakeman v7.0.2
Updated Jan 7, 2026 - #1977
Provide a way to report warnings only from some files/directories while scanning the full app
Updated Nov 20, 2025 - #1533
Ignore comment in Regex
Updated Oct 15, 2025 - #1945
Brakeman enum support broken?
Updated Jul 9, 2025