PkgRadar

PyPI · pypi.org

codehydra

Py Import Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Why PkgRadar flagged 2026.6.9

SeveritySignalEvidence
highPy Import Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · codehydra-2026.6.9/src/codehydra/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · codehydra-2026.6.9/src/codehydra/__init__.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.9High risk972026-06-09

Block this in CI

PkgRadar gates codehydra (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi codehydra==2026.6.9