Show HN: Octotrack – automatic dependency and security manager for Ruby apps
octotrack.com
octotrack.com
It's a big ask, and a lot of trust for some Show HN. I'd like to be able to get info on pricing, poke around, and test stuff, before I give away the keys to the castle.
Octotrack is not requesting full access to Github, only to the public information and inherently public repos. But nothing concerning private information, that was one of the main objectives.
It would be great if you could try it out. Thank you :)
Now the only information shared is the user's public information.
Thank you
"This application will be able to read and write all user data. This includes the following:
Private email addresses Private profile information Followers"
Regarding pricing, this is a new public page with the pricing since it was only available after you logged in - https://www.octotrack.com/pricing.
Thank you
The pain is definitely real. We had a 6-year-old rails app that got upgraded from Rails 2.3 and keeping track of dependency decay was painful.
Looking at your landing page, I could not understand how are you solving the problem exactly. The screenshots don't expand so I don't really get the solution.
One very nice feature that you can add and will help a lot is to support comment parsing in the Gemfile and Gemfile.lock. Something like email: my@my.com. When you parse the file, send me the report and don't make me actively visit the page.
Also offer a sample report on your page by submitting a public repo perhaps.
Good luck!
I'll provide a sample report on the landing page, add a way to expand the screenshots and provide more information on the sign up process. Octotrack does not access the repositories directly, that was one of the main objectives. Only your email and github public information. Once you create a project, you'll have the option to upload a Gemfile.lock or add a git post-commit hook to your project. From then on, you'll have access to the security vulnerabilities that exist and what dependencies need to be updated as well as other information (such as release notes, etc).
Once again, thank you for the feedback and hope it solves a real pain.
1: https://github.com/rubysec/bundler-audit
2: https://gist.github.com/andrewhampton/d78df6952e757fd1038401...
With Octotrack you'll receive an email digest every morning informing you of the latest updates of the gems you use as well as possible vulnerabilities recently discovered.
Please let me know if this is valuable information for you.
Thank you very much for your feedback.
Most of the times I just want to know about a new release and not actually have a PR created for it. I'm also not sure if dependabot warns about vulnerabilities. Nevertheless, I believe they can be used in conjunction and not as a replacement.
You have two ways to update your dependencies:
1. Manually upload your gemfile.lock.
2. Intall a post-commit hook which only sends the gemfile.lock in case it was changed.
It would be great if you could try it out.
Thank you.
1. Shows dependencies relationships
2. Automatic updates without the need to request access to the whole project (via git post-commit hook)
3. Analysis of most used dependencies on all your projects
4. Daily emails divided per project instead of dependency / gem
5. Cheaper and with 1 free private project
This is a new project so all feedback is more than welcome. I'm looking to develop everything that makes the platform better and helps every developer and tech team.