PkgRadar

PyPI · pypi.org

attestor

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 4.1.11

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · attestor-4.1.11/attestor/consolidation/reflection.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · attestor-4.1.11/attestor/extraction/llm_entity_extractor.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.1.11High risk532026-05-30
4.1.10High risk532026-05-30
4.1.8High risk532026-05-30
4.1.7High risk532026-05-30
4.1.6High risk532026-05-30
4.1.5High risk532026-05-30
4.1.4High risk532026-05-30
4.1.3High risk532026-05-30
4.1.2High risk532026-05-30
4.1.1High risk532026-05-30

Block this in CI

PkgRadar gates attestor (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi attestor==4.1.11