Surfguard resolves a hostname to the public IP addresses it points at and refuses anything that would reach an internal network: private, loopback, link-local and carrier-grade NAT space, plus the IPv6 transition ranges a naive guard misses (IPv4-mapped, SIIT, NAT64, 6to4, Teredo). It resolves and classifies only; the caller owns the fetch and pins the connection to a returned address so DNS rebinding cannot swap in a blocked one. Standard library only, no runtime dependencies.
Required Ruby Version
>= 3.4.5
Authors
37signals
Versions
-
0.2.0
-
source
- 0.2.0 source August 31, 2026 (14 KB)
-
-
0.1.3
-
source
- 0.1.3 source August 13, 2026 (15 KB)
-
-
0.1.2
-
source
- 0.1.2 source August 12, 2026 (14.5 KB)
-
-
0.1.1
-
source
- 0.1.1 source August 12, 2026 (14.5 KB)
-
-
0.1.0
-
source
- 0.1.0 source August 12, 2026 (12 KB)
-