// the find
eliotsykes/rails-security-checklist
:key: Community-driven Rails Security Checklist (see our GitHub Issues for the newest checks that aren't yet in the README)
A community-maintained checklist of Rails security practices, written as one long Markdown file rather than code. It is for Rails developers who want a list to work through before shipping, and it says up front that it was drafted by a developer rather than a security expert.
The concrete snippets are where the value is. The token lookup example separates finding the user by a non-secret identifier from comparing the secret, and it uses SHA256 digests with ActiveSupport::SecurityUtils.secure_compare so the comparison doesn't leak length. The ERB-versus-HTML comment example and the regex anchor note name specific mistakes that generic checklists skip. Items like verify_authorized and verify_policy_scoped point at real Pundit mechanisms instead of telling you to 'do authorization', and the case for duplicating checks in routes.rb as defense in depth is worth reading even if you end up disagreeing with it.
The last push was July 2022, more than four years ago, and nothing in the repo says it is maintained. Several references (the plataformatec Devise wiki, thisdata.com, the Sqreen CTO checklist) are the kind that go stale. The list is long and flat, with no severity ranking, no way to tell which items apply to a given app, and no verification step for most of them. Some entries aren't actionable yet: the random token section is marked CONTRIBUTOR NEEDED, and the Redis section ends by asking whether its own advice applies to most setups. The logging snippet also contradicts its text. It says a safelist is preferable, then adds a match-all regex to filter_parameters, which is still a blocklist that happens to match everything.