PkgRadar

PyPI · pypi.org

annet

Py Import Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Why PkgRadar flagged 4.2.7

SeveritySignalEvidence
highPy Import Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · annet-4.2.7/annet/api/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.2.7High risk252026-06-16
4.2.6High risk252026-06-16
4.2.5High risk252026-06-11
4.2.4High risk252026-06-11
4.2.3High risk252026-06-09
4.2.2High risk252026-06-09
4.2.1High risk252026-06-08
4.2.0High risk252026-06-04
4.1.0High risk252026-06-03
4.0.0High risk252026-06-02
3.30.7High risk252026-05-30
3.30.6High risk252026-05-30
3.30.5High risk252026-05-30

Block this in CI

PkgRadar gates annet (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi annet==4.2.7