PkgRadar

PyPI · pypi.org

dh-cli

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.8.8

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · dh_cli-0.8.8/src/dh_cli/hz/__init__.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · dh_cli-0.8.8/src/dh_cli/hz/test.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · dh_cli-0.8.8/src/dh_cli/cloud_commands.py
mediumCredential file accessmatched ".ssh/" · dh_cli-0.8.8/src/dh_cli/engines_studios/engine_commands.py
mediumCredential file accessmatched ".ssh/" · dh_cli-0.8.8/src/dh_cli/engines_studios/ssh_config.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.8High risk972026-06-02

Block this in CI

PkgRadar gates dh-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi dh-cli==0.8.8