PyPI · pypi.org
asreview
Py Install Time Subprocess: subprocess call — process spawning.
Why PkgRadar flagged 3.0.7
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Subprocess | subprocess call — process spawning. · asreview-3.0.7/setup.py |
| medium | Remote Payload | matched "raw.githubusercontent.com" · asreview-3.0.7/asreview/webapp/src/api/UtilsAPI.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.0.7 | Review | 18 | 2026-06-03 |
3.0.6 | Review | 18 | 2026-06-01 |
Block this in CI
pkgradar gate --ecosystem pypi asreview==3.0.7