PkgRadar

PyPI · pypi.org

coverage

Py Runtime Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 7.14.1

SeveritySignalEvidence
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · coverage/templite.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · coverage/execfile.py
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · coverage/execfile.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · coverage/xmlreport.py

Scanned versions

VersionVerdictScoreScanned (UTC)
7.14.1Review182026-05-26

Block this in CI

PkgRadar gates coverage (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi coverage==7.14.1