PkgRadar

PyPI · pypi.org

buildai-cli

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 0.3.87

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · buildai_cli-0.3.87/cli/internal_api.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.87High risk302026-06-06
0.3.86High risk302026-06-06
0.3.85High risk302026-06-06
0.3.84High risk302026-06-06
0.3.83High risk302026-06-06
0.3.82High risk302026-06-04
0.3.81High risk302026-06-04
0.3.80High risk302026-06-03
0.3.79High risk302026-05-30
0.3.78High risk302026-05-30
0.3.77High risk302026-05-30
0.3.76High risk302026-05-30

Block this in CI

PkgRadar gates buildai-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi buildai-cli==0.3.87