PkgRadar

PyPI · pypi.org

ddtrace

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 4.10.4

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · ddtrace/vendor/psutil/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · ddtrace/appsec/_iast/__init__.py
mediumLarge Native Blob7371520 bytes · ddtrace/internal/native/_native.cpython-310-darwin.so

Scanned versions

VersionVerdictScoreScanned (UTC)
4.10.4Review222026-06-10
4.11.0rc2Review222026-06-10
4.8.9Review222026-06-10
4.10.3Review222026-06-08
4.9.1Review222026-06-08
4.8.8Review222026-06-05
4.10.2Review222026-06-04
4.11.0rc1Review372026-06-03
4.10.1Review222026-06-01
4.10.0Review222026-05-29
4.10.0rc1Review572026-05-27

Block this in CI

PkgRadar gates ddtrace (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ddtrace==4.10.4