PkgRadar

RubyGems · rubygems.org

bolognese

Rb Install Time Backticks: Backtick subshell or %x() shell-out — runs shell with interpolated input.

Why PkgRadar flagged 2.7.0

SeveritySignalEvidence
highRb Install Time BackticksBacktick subshell or %x() shell-out — runs shell with interpolated input. · bolognese.gemspec
mediumRemote Payloadmatched "raw.githubusercontent.com" · lib/bolognese/utils.rb
mediumRemote Payloadmatched "raw.githubusercontent.com" · lib/bolognese/writers/codemeta_writer.rb

Scanned versions

VersionVerdictScoreScanned (UTC)
2.7.0Review222026-05-27

Block this in CI

PkgRadar gates bolognese (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem rubygems [email protected]