Categories: None [Edit]

still_active

https://rubygems.org/gems/still_active
https://github.com/SeanLF/still_active
Analyses your Gemfile.lock for dependency health across the full transitive graph: whether each gem is actively maintained (last activity on GitHub, GitLab, or Codeberg/Forgejo, plus release recency), outdated versions, archived repos, OpenSSF Scorecard scores, known vulnerabilities (deps.dev and OSV, merged with ruby-advisory-db, flagging advisories with no fix and pins that sit below the fix), poison-pill compatibility ceilings, and libyear drift. Ruby version freshness with EOL detection. The same maintenance lens travels cross-ecosystem: point --sbom at a CycloneDX SBOM to assess npm, PyPI, Cargo, Go, Maven, and NuGet packages via deps.dev and ecosyste.ms. Handles rubygems, git, path, GitHub Packages, and JFrog Artifactory sources. Outputs coloured terminal tables, markdown, JSON (with a versioned, contract-tested schema), SARIF for GitHub code scanning, and a CycloneDX SBOM. CI quality gates (--fail-if-critical / -warning / -vulnerable / -outdated / -poison / -language-ceiling) with granular, committed suppression via .still_active.yml. Complements bundle outdated, bundler-audit, and libyear-bundler by adding the maintenance signal they don't, and folds their version, CVE, and libyear checks into one report.

Total

Ranking: 59,643 of 196,721
Downloads: 18,975

Daily

Ranking: 17,634 of 196,694
Downloads: 13

Depended by

RankDownloadsName

Depends on

RankDownloadsName
13,728,237,794bundler
123410,316,502faraday-retry
131392,464,004octokit
85265,268,897semantic_range
94255,162,062gems
98252,949,718async
1,64623,750,131cvss-suite
17,044117,902packageurl-ruby

Owners

#GravatarHandle
1iconseanlf