> dependencies such as Rubygems are and will always be part of your app's Trusted Computing Base
This mindset is changing, in the npm ecosystem, managing and updating dependencies have become somewhat of a gamble. It is no longer if, its when you are compromised.
Checksumming the dependencies in the Gemfile may help. https://blog.rubygems.org/2024/12/19/bundler-v2-6.html
Gems/packages should explicitly declare what kind of features they need/want (file, net, deserialization, execute)
And when the sig. changes, you should get a warning
Very similar to the iOS entitlements