Skip to content

Exclude Gemfile.lock from gem package to avoid false positive security alerts#70

Merged
fuelen merged 1 commit intojetruby:masterfrom
SuguruMatsumoto-rni:exclude-gemfile-lock
Jan 29, 2026
Merged

Exclude Gemfile.lock from gem package to avoid false positive security alerts#70
fuelen merged 1 commit intojetruby:masterfrom
SuguruMatsumoto-rni:exclude-gemfile-lock

Conversation

@SuguruMatsumoto-rni
Copy link
Contributor

Summary

Exclude Gemfile.lock from the gem package to prevent false positive vulnerability alerts from security scanners like Amazon Inspector.

Problem

Security scanners (e.g., Amazon ECR Enhanced Scanning, Amazon Inspector) scan all files in container images, including Gemfile.lock files inside gem packages. The development Gemfile.lock in this gem references older versions of dependencies (e.g., actionpack 7.0.4), which triggers vulnerability alerts even though applications using this gem typically have newer, patched versions.

Reference: https://tech.medpeer.co.jp/entry/ecr-enhanced-scanning-false-positive

Solution

Exclude Gemfile.lock from spec.files in the gemspec, as it's only used during gem development and not needed at runtime.

@fuelen fuelen merged commit cc2747b into jetruby:master Jan 29, 2026
0 of 3 checks passed
@fuelen
Copy link
Collaborator

fuelen commented Jan 29, 2026

Thank you!

@fuelen fuelen mentioned this pull request Jan 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants