PkgRadar

PyPI · pypi.org

deepy-cli

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.2.30

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · deepy_cli-0.2.30/src/deepy/ui/shared/local_command/__init__.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.30Review572026-06-05
0.2.29Review252026-06-03
0.2.28Review252026-06-02
0.2.27Review252026-06-02
0.2.26Review252026-05-31
0.2.25Review252026-05-28
0.2.24Review252026-05-28
0.2.23Review372026-05-27
0.2.22Review372026-05-27

Block this in CI

PkgRadar gates deepy-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi deepy-cli==0.2.30