PkgRadar

PyPI · pypi.org

coevopy

Py Install Time Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 0.4

SeveritySignalEvidence
highPy Install Time Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · coevopy-0.4/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4High risk502026-05-31

Block this in CI

PkgRadar gates coevopy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi coevopy==0.4
coevopy — PyPI security scan | PkgRadar