PkgRadar

PyPI · pypi.org

c2cciutils

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 1.4.27.dev35

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · c2cciutils-1.4.27.dev35/c2cciutils/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · c2cciutils-1.4.27.dev35/c2cciutils/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.27.dev35Review142026-06-11
1.6.25.dev75Review142026-06-11
1.5.18.dev62Review142026-06-11
1.3.28.dev31Review142026-06-11
1.1.dev20260611010041Review142026-06-11
1.7.7.dev66Review172026-06-10
1.6.25.dev74Review142026-06-10
1.5.18.dev61Review142026-06-10
1.7.7.dev64Review172026-06-10
1.5.18.dev59Review142026-06-10
1.3.28.dev28Review142026-06-10
1.4.27.dev34Review142026-06-10
1.6.25.dev72Review142026-06-10
1.7.7.dev62Review172026-06-08
1.6.25.dev70Review142026-06-08
1.5.18.dev57Review142026-06-08
1.1.dev20260608080955Review142026-06-08
1.6.25.dev68Review142026-06-05
1.6.25.dev66Review142026-06-03
1.5.18.dev55Review142026-06-03
1.3.28.dev26Review142026-06-03
1.7.7.dev60Review172026-06-02
1.6.25.dev63Review142026-06-02
1.5.18.dev52Review142026-06-02
1.4.27.dev32Review142026-06-02
1.7.7.dev56Review172026-06-01
1.6.25.dev61Review142026-06-01
1.5.18.dev50Review142026-06-01
1.4.27.dev30Review142026-06-01
1.4.27.dev28Review142026-06-01
1.5.18.dev48Review142026-06-01
1.6.25.dev59Review142026-06-01
1.3.28.dev23Review142026-06-01
1.7.7.dev53Review342026-05-27
1.6.25.dev58Review312026-05-27
1.5.18.dev47Review492026-05-27

Block this in CI

PkgRadar gates c2cciutils (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi c2cciutils==1.4.27.dev35