PkgRadar

PyPI · pypi.org

cirq-core

Py Runtime Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 1.7.0.dev20260526195242

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call — process spawning. · cirq/contrib/quantikz/circuit_to_latex_render.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · cirq/_compat_test.py
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · cirq/circuits/insert_strategy_test.py
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · cirq/devices/grid_qubit_test.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · cirq/experiments/two_qubit_xeb_test.py
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · cirq/protocols/hash_from_pickle_test.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · cirq/protocols/json_serialization_test.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · cirq/testing/equivalent_repr_eval.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · cirq/value/linear_dict_test.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · cirq/value/product_state_test.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.7.0.dev20260613151434Low risk02026-06-13
1.7.0.dev20260612235300Low risk02026-06-13
1.7.0.dev20260608233335Low risk02026-06-08
1.7.0.dev20260605181515Low risk02026-06-05
1.7.0.dev20260604221749Low risk02026-06-04
1.7.0.dev20260604022051Low risk02026-06-04
1.7.0.dev20260601223209Low risk02026-06-01
1.7.0.dev20260530040123Low risk02026-05-30
1.7.0.dev20260530000804Low risk02026-05-30
1.7.0.dev20260529222919Low risk02026-05-29
1.7.0.dev20260527204322Low risk02026-05-27
1.7.0.dev20260527161107Low risk02026-05-27
1.7.0.dev20260526195242Review342026-05-26

Block this in CI

PkgRadar gates cirq-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi cirq-core==1.7.0.dev20260526195242