PkgRadar

RubyGems · rubygems.org

parse-stack-next

Rb Install Time System: Direct shell invocation paired with eval/dynamic-require/network/deserialize.

Why PkgRadar flagged 5.1.0

SeveritySignalEvidence
highRb Install Time SystemDirect shell invocation paired with eval/dynamic-require/network/deserialize. · Rakefile
highRb Install Time BackticksBacktick / %x() shell-out paired with eval/dynamic-require/network/deserialize. · Rakefile
highRb Install Time Network CallNetwork call (Net::HTTP / URI.open / HTTParty / Faraday / RestClient) at install time. · Rakefile

Scanned versions

VersionVerdictScoreScanned (UTC)
5.1.0High risk1362026-06-03

Related campaigns

Block this in CI

PkgRadar gates parse-stack-next (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem rubygems [email protected]