PkgRadar

PyPI · pypi.org

bspctl

Py Runtime Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.4.0

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/diagnostics.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/layers.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/steps/bitbake_override.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/steps/kas_build.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/steps/repo.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/steps/run_qemu.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/steps/setup_env.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/steps/ti_layertool.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · bspctl-0.4.0/src/bspctl/workspace.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml
mediumRemote Payloadmatched "wget " · bspctl-0.4.0/src/bspctl/overlays/bspctl-tuning-ti.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.0High risk772026-05-26

Block this in CI

PkgRadar gates bspctl (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi bspctl==0.4.0
bspctl — PyPI security scan | PkgRadar