PkgRadar

RubyGems · rubygems.org

plutonium

Credential File Packaged: lib/generators/pu/gem/dotenv/templates/.env

Why PkgRadar flagged 0.60.4

SeveritySignalEvidence
highCredential File Packagedlib/generators/pu/gem/dotenv/templates/.env · lib/generators/pu/gem/dotenv/templates/.env
mediumRemote Payloadmatched "curl " · lib/generators/pu/service/postgres/postgres_generator.rb

Scanned versions

VersionVerdictScoreScanned (UTC)
0.60.4High risk232026-06-15
0.60.3High risk232026-06-15
0.60.2High risk232026-06-15
0.60.1High risk232026-06-15
0.60.0High risk232026-06-14
0.59.0High risk232026-06-13
0.58.1High risk232026-06-10
0.58.0High risk232026-06-10
0.57.0High risk232026-06-09
0.56.3High risk232026-06-07
0.56.2High risk232026-06-05
0.56.1High risk232026-06-05
0.56.0High risk232026-06-05
0.55.0High risk232026-06-03
0.54.0High risk232026-06-01
0.53.1High risk232026-05-31
0.53.0High risk232026-05-31

Block this in CI

PkgRadar gates plutonium (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem rubygems [email protected]