PkgRadar

PyPI · pypi.org

aps-beamline-driver

Py Runtime Pickle Loads: pickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled.

Why PkgRadar flagged 1.0.27

SeveritySignalEvidence
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · aps_beamline_driver-1.0.27/aps/beamline_driver/beam_management/facade.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.41Low risk02026-06-12
1.0.40Low risk02026-06-12
1.0.39Low risk02026-06-12
1.0.38Low risk02026-06-12
1.0.37Low risk02026-06-12
1.0.36Low risk02026-06-11
1.0.35Low risk02026-06-11
1.0.34Low risk02026-06-11
1.0.33Low risk02026-06-11
1.0.32Low risk02026-06-10
1.0.31Low risk02026-06-09
1.0.30Low risk02026-06-09
1.0.29Low risk02026-06-09
1.0.28Low risk02026-05-26
1.0.27Review202026-05-26
1.0.26Review202026-05-26

Block this in CI

PkgRadar gates aps-beamline-driver (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aps-beamline-driver==1.0.27