I'm not sure how it compares with Octotrack, but we've been using bundler-audit[1] for similar security checks in our dependencies. Here's a sample Dockerfile[2] for running bundler-audit against your Gemfile and Gemfile.lock
1: https://github.com/rubysec/bundler-audit
2: https://gist.github.com/andrewhampton/d78df6952e757fd1038401...