PkgRadar

PyPI · pypi.org

docutils

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.23

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · docutils-0.23/docutils/writers/odf_odt/__init__.py
mediumRemote Payloadmatched "curl\n " · docutils-0.23/docutils/nodes.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.23Review222026-05-27

Block this in CI

PkgRadar gates docutils (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi docutils==0.23