PkgRadar

PyPI · pypi.org

colonyai

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.21.8

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · colonyai-0.21.8/colony_sidecar/setup.py
mediumPy Install Time Subprocesssubprocess call — process spawning. · colonyai-0.21.8/colony_sidecar/vector/setup.py
mediumRemote Payloadmatched "curl " · colonyai-0.21.8/colony_sidecar/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.21.8Review622026-06-11
0.21.7Review622026-06-11
0.21.6Review622026-06-11
0.21.5Review622026-06-11
0.21.4Review622026-06-11
0.21.3Review622026-06-11
0.21.2Review622026-06-11
0.21.0Review622026-06-11
0.20.0Review622026-06-10
0.19.0Review622026-06-10
0.18.0Review622026-06-10
0.17.0Review622026-06-10
0.16.0Review622026-06-10

Block this in CI

PkgRadar gates colonyai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi colonyai==0.21.8