PkgRadar

RubyGems · rubygems.org

appsignal

Rb Install Time System: Direct shell invocation paired with eval/dynamic-require/network/deserialize.

Why PkgRadar flagged 4.8.5

SeveritySignalEvidence
highRb Install Time SystemDirect shell invocation paired with eval/dynamic-require/network/deserialize. · Rakefile
highRb Install Time BackticksBacktick / %x() shell-out paired with eval/dynamic-require/network/deserialize. · Rakefile
highRb Install Time Unsafe DeserializeMarshal.load / YAML.unsafe_load — RCE if attacker-controlled. · Rakefile
mediumRb Install Time Evaleval / instance_eval / class_eval — evaluates Ruby from a string. · Rakefile

Scanned versions

VersionVerdictScoreScanned (UTC)
4.8.5Review582026-06-02

Block this in CI

PkgRadar gates appsignal (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem rubygems [email protected]