PkgRadar

PyPI · pypi.org

eplang

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 9.7.0

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · eplang-9.7.0/epl/js_bridge/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · eplang-9.7.0/epl/official_packages/epl-auth/python/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
9.7.0High risk482026-06-16
9.6.0High risk482026-06-14
9.5.0High risk482026-06-13
9.4.0High risk482026-06-05
9.3.0High risk482026-06-01
9.1.0High risk482026-06-01

Block this in CI

PkgRadar gates eplang (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi eplang==9.7.0