>Rubysec is awesome but outdated, lacks many of the vulnerabilities in https://Snyk.io/
I'm one of the Rubysec maintainers.
If you're reading this and you know about vulns not present in the advisory-db, please submit a PR to the github repo, or use the crappy form we put together: https://rubysec.com/advisories/new
I too run a vulnerability notification service, and it's frustrating when other people use public data but don't contribute back.
Also, Snyk covers JS issues, both Nodd and client side