Categories: None [Edit]

still_active

https://rubygems.org/gems/still_active
https://github.com/SeanLF/still_active
Analyses your Gemfile.lock for dependency health across the full transitive graph: whether each gem is actively maintained (last activity on GitHub, GitLab, or Codeberg/Forgejo, plus release recency), outdated versions, archived repos, OpenSSF Scorecard scores, known vulnerabilities (deps.dev and OSV, merged with ruby-advisory-db, flagging advisories with no fix and pins that sit below the fix), poison-pill compatibility ceilings, and libyear drift. Ruby version freshness with EOL detection. The same maintenance lens travels cross-ecosystem: point --sbom at a CycloneDX SBOM to assess npm, PyPI, Cargo, Go, Maven, and NuGet packages via deps.dev and ecosyste.ms. Handles rubygems, git, path, GitHub Packages, and JFrog Artifactory sources. Outputs coloured terminal tables, markdown, JSON (with a versioned, contract-tested schema), SARIF for GitHub code scanning, and a CycloneDX SBOM. CI quality gates (--fail-if-critical / -warning / -vulnerable / -outdated / -poison / -language-ceiling) with granular, committed suppression via .still_active.yml. Complements bundle outdated, bundler-audit, and libyear-bundler by adding the maintenance signal they don't, and folds their version, CVE, and libyear checks into one report.

Total

Ranking: 57,616 of 197,051
Downloads: 19,967

Daily

Ranking: 28,115 of 197,010
Downloads: 5

Depended by

RankDownloadsName

Depends on

RankDownloadsName
13,792,501,566bundler
122417,016,633faraday-retry
131396,036,138octokit
84965,893,075semantic_range
97053,989,908async
1,65323,813,978cvss-suite
16,925120,659packageurl-ruby

Owners

#GravatarHandle
1iconseanlf