PkgRadar

RubyGems · rubygems.org

spree_cm_commissioner

Rb Install Time System: Direct shell invocation paired with eval/dynamic-require/network/deserialize.

Why PkgRadar flagged 2.8.3.pre.pre7

SeveritySignalEvidence
highRb Install Time SystemDirect shell invocation paired with eval/dynamic-require/network/deserialize. · Rakefile
highRb Install Time Unsafe DeserializeMarshal.load / YAML.unsafe_load — RCE if attacker-controlled. · Rakefile
highCredential file accessmatched "AWS_ACCESS_KEY" · app/interactors/spree_cm_commissioner/invalidate_cache_request.rb
highCredential file accessmatched "AWS_ACCESS_KEY" · app/interactors/spree_cm_commissioner/waiting_room_latest_system_metadata_puller.rb
highCredential file accessmatched "AWS_ACCESS_KEY" · lib/spree_cm_commissioner/s3_url_generator.rb

Scanned versions

VersionVerdictScoreScanned (UTC)
2.8.3.pre.pre7High risk752026-06-13
2.8.3.pre6High risk752026-06-10
2.8.3.pre.pre5High risk752026-06-09
2.8.3.pre.pre4High risk752026-06-08
2.8.3High risk752026-06-05
2.8.3.pre.pre1High risk752026-06-04
2.8.2.pre.pre.9High risk752026-06-02
2.8.2.pre.pre.8High risk752026-06-02
2.8.2.pre.pre.7High risk752026-06-02
2.8.2.pre.pre.6High risk752026-06-02
2.8.2.pre.pre.5High risk752026-06-01
2.8.2.pre.pre.4High risk752026-06-01
2.8.2.pre.pre.3High risk752026-06-01
2.8.2.pre.pre.2High risk752026-05-31
2.8.2High risk752026-05-30
2.8.2.pre.pre.1High risk752026-05-30
2.8.1.pre.pre.4High risk752026-05-30

Block this in CI

PkgRadar gates spree_cm_commissioner (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem rubygems [email protected]