Skip to content

History / R8 A03 Supply Chain

Revisions

  • Update Rails 8 wiki to align with OWASP Top 10 2025 Restructured Rails 8 tutorials to follow OWASP Top 10 2025 framework and added comprehensive A03 Software Supply Chain tutorial. ## Changes to Rails-8-Tutorials.md - Reorganized all content to follow OWASP 2025 structure (A01-A10:2025) - Mapped all existing vulnerabilities to correct 2025 categories - Added A03 Software Supply Chain Failures section (NEW) - Updated quick reference table with OWASP 2025 category mappings - Added demonstration endpoint documentation - Comprehensive Rails 5 vs Rails 8 security comparison ## New Tutorial: R8-A03-Supply-Chain.md Created comprehensive 500+ line tutorial covering: - Missing Subresource Integrity (SRI) on CDN assets - Outdated dependencies and CVE tracking - Lack of Software Bill of Materials (SBOM) - Insecure gem sources - Dependency integrity validation Includes: - Real-world breach examples (British Airways, SolarWinds, Log4Shell) - Demonstration endpoints (/tutorials/supply_chain, /tutorials/check_dependencies) - Exploitation scenarios and attack vectors - Mitigation strategies and best practices - Tools and resources (bundler-audit, Dependabot, Snyk, CycloneDX) - Rails 8 specific guidance - Complete testing instructions ## OWASP 2025 Coverage Now documents 100% coverage of OWASP Top 10 2025: - A01:2025 - Broken Access Control - A02:2025 - Security Misconfiguration - A03:2025 - Software Supply Chain Failures (NEW) - A04:2025 - Cryptographic Failures - A05:2025 - Injection (including NEW ReDoS) - A06:2025 - Insecure Design - A07:2025 - Authentication Failures - A08:2025 - Data Integrity Failures - A09:2025 - Security Logging and Monitoring Failures - A10:2025 - Exception Mishandling 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>

    @cktricky cktricky committed Dec 6, 2025