PkgRadar

PyPI · pypi.org

csaw

Py Import Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Why PkgRadar flagged 0.10.0

SeveritySignalEvidence
highPy Import Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · csaw/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · csaw/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.0High risk412026-06-10
0.9.0High risk572026-06-09
0.8.2High risk572026-05-30
0.8.1High risk572026-05-30
0.8.0High risk572026-05-30
0.7.2High risk572026-05-30

Block this in CI

PkgRadar gates csaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi csaw==0.10.0