PkgRadar

RubyGems · rubygems.org

ory-client

Rb Install Time Backticks: Backtick / %x() shell-out paired with eval/dynamic-require/network/deserialize.

Why PkgRadar flagged 1.22.43

SeveritySignalEvidence
highRb Install Time BackticksBacktick / %x() shell-out paired with eval/dynamic-require/network/deserialize. · vendor/bundle/ruby/3.2.0/gems/method_source-1.1.0/Rakefile
highRb Install Time BackticksBacktick / %x() shell-out paired with eval/dynamic-require/network/deserialize. · vendor/bundle/ruby/3.2.0/gems/psych-4.0.6/psych.gemspec
mediumRb Install Time Dynamic Requirerequire() with string interpolation — runtime-resolved library path. · vendor/bundle/ruby/3.2.0/gems/method_source-1.1.0/Rakefile
mediumRb Install Time Evaleval / instance_eval / class_eval — evaluates Ruby from a string. · vendor/bundle/ruby/3.2.0/gems/psych-4.0.6/psych.gemspec
mediumRemote Payloadmatched "wget " · vendor/bundle/ruby/3.2.0/gems/coderay-1.1.3/lib/coderay/scanners/lua.rb
mediumRemote Payloadmatched "curl " · vendor/bundle/ruby/3.2.0/gems/ethon-0.18.0/ethon.gemspec
mediumRemote Payloadmatched "Curl\n " · vendor/bundle/ruby/3.2.0/gems/ethon-0.18.0/lib/ethon/curl.rb
mediumRemote Payloadmatched "Curl\n " · vendor/bundle/ruby/3.2.0/gems/ethon-0.18.0/lib/ethon/curls/classes.rb
mediumRemote Payloadmatched "Curl\n " · vendor/bundle/ruby/3.2.0/gems/ethon-0.18.0/lib/ethon/curls/constants.rb
mediumRemote Payloadmatched "Curl\n " · vendor/bundle/ruby/3.2.0/gems/ethon-0.18.0/lib/ethon/curls/settings.rb
mediumRemote Payloadmatched "curl " · vendor/bundle/ruby/3.2.0/gems/typhoeus-1.6.0/typhoeus.gemspec
mediumRemote Payloadmatched "curl " · vendor/bundle/ruby/3.2.0/specifications/ethon-0.18.0.gemspec

Scanned versions

VersionVerdictScoreScanned (UTC)
1.22.53Low risk02026-06-17
1.22.52Low risk02026-06-16
1.22.51Low risk02026-06-12
1.22.50Low risk02026-06-11
1.22.49Low risk02026-06-10
1.22.48Low risk02026-06-05
1.22.47Low risk02026-06-03
1.22.46Low risk02026-06-03
1.22.45Low risk02026-06-03
1.22.44Low risk02026-06-03
1.22.43Review722026-05-29

Block this in CI

PkgRadar gates ory-client (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem rubygems [email protected]