PyPI · pypi.org
duckframework
Credential File Packaged: duckframework-2.0.0/duck/etc/structures/projects/full/.env
Why PkgRadar flagged 2.0.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential File Packaged | duckframework-2.0.0/duck/etc/structures/projects/full/.env · duckframework-2.0.0/duck/etc/structures/projects/full/.env |
| medium | Py Import Time Eval Exec | Python eval()/exec() called on a string. · duckframework-2.0.0/duck/html/components/templatetags/__init__.py |
| high | Py Import Time Raw Socket | Raw socket creation at install or import time. · duckframework-2.0.0/duck/utils/xsocket/__init__.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.0.0 | High risk | 69 | 2026-06-08 |
Block this in CI
pkgradar gate --ecosystem pypi duckframework==2.0.0