rubysec / bundler-audit

Patch-level verification for Bundler
GNU General Public License v3.0
2.68k stars 228 forks source link

No longer set `test_files` in the gemspec #361

Open postmodern opened 2 years ago

postmodern commented 2 years ago

Rubocop complains about gemspec.test_files plus the test-files contain insecure Gemfile.lock files which can sometimes trigger other vulnerability scanners when they scan bundler-audit.