PkgRadar

PyPI · pypi.org

dve-lumipy-testing

Py Import Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Why PkgRadar flagged 1.0.639

SeveritySignalEvidence
highPy Import Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · lumipy/__init__.py
highPy Import Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · lumipy/provider/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.639High risk252026-06-12
1.0.638High risk252026-06-12
1.0.637High risk252026-06-11
1.0.636High risk252026-06-11
1.0.635High risk252026-06-10
1.0.634High risk252026-06-08
1.0.633High risk252026-06-08
1.0.632High risk252026-06-05
1.0.631High risk252026-06-05
1.0.630High risk252026-06-04
1.0.629High risk252026-06-04
1.0.628High risk252026-06-04
1.0.627High risk252026-06-03
1.0.626High risk252026-06-03
1.0.625High risk252026-05-30
1.0.624High risk252026-05-30

Block this in CI

PkgRadar gates dve-lumipy-testing (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi dve-lumipy-testing==1.0.639