1
I Use This!
Moderate Activity
Analyzed about 7 hours ago. based on code collected 1 day ago.

Project Summary

Web Application for the Ohloh Stack. Currently Rails 4.2.7 & Ruby 2.2.5

Tags

blackduck openhub oss postgresql rails ruby rubyonrails

Apache License 2.0
Permitted

Commercial Use

Modify

Distribute

Place Warranty

Sub-License

Private Use

Use Patent Claims

Forbidden

Hold Liable

Use Trademarks

Required

Include Copyright

State Changes

Include License

Include Notice

These details are provided for information only. No information here is legal advice and should not be used as such.

Project Security

Vulnerabilities per Version ( last 10 releases )

There are no reported vulnerabilities

Project Vulnerability Report

Security Confidence Index

Poor security track-record
Favorable security track-record

Vulnerability Exposure Index

Many reported vulnerabilities
Few reported vulnerabilities

Did You Know...

  • ...
    65% of companies leverage OSS to speed application development in 2016
  • ...
    learn about Open Hub updates and features on the Open Hub blog
  • ...
    there are over 3,000 projects on the Open Hub with security vulnerabilities reported against them
  • ...
    anyone with an Open Hub account can update a project's tags
About Project Security

Languages

Ruby
63%
SQL
19%
JavaScript
8%
7 Other
10%

30 Day Summary

Apr 10 2024 — May 10 2024

12 Month Summary

May 10 2023 — May 10 2024
  • 88 Commits
    Down -7 (7%) from previous 12 months
  • 4 Contributors
    Down -4 (50%) from previous 12 months

Ratings

1 user rates this project:
5.0
 
5.0/5.0
Click to add your rating
  
Review this Project!
 

Static Analysis ( Generated by Coverity Scan for Ohloh UI )

Repository URL: https://github.com/blackducksoftware/ohloh-ui

Version: b15e2a1b3d77d7c0d3f7e3d91827e109e6b2dccd

2024-05-02
Last Analyzed
1,011,256
Lines of Code Analyze
1.02
Defect Density

Defects by status for current build

217
Total defects
113
Outstanding
53
Fixed

CWE Top 25 defects

ID CWE-Name Number of Defects
78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 6
352 Cross-Site Request Forgery (CSRF) 1
676 Use of Potentially Dangerous Function 5
798 Use of Hard-coded Credentials 37
829 Inclusion of Functionality from Untrusted Control Sphere 2
862 Missing Authorization 11