On exactly this subject, I'm in the process of building a SaaS app that will alert you of security vulnerabilities in Gems in your Rails and other Ruby apps.
Sign up at my landing page to here more when I'm closer to launch
Sign up at my landing page to here more when I'm closer to launch
Try it now.
Thanks
My preference would be to upload that Gemfile.lock to a location, and then it could be scanned as and when new vulnerabilities were detected.
Making this automatic is the key part - if you don't get burned very often, you'll eventually forget to do the right thing manually and open yourselves to badness.