PkgRadar

PyPI · pypi.org

esphome

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 2026.6.0b3

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · esphome-2026.6.0b3/esphome/analyze_memory/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · esphome-2026.6.0b3/esphome/components/esp32/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · esphome-2026.6.0b3/esphome/components/esp8266/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · esphome-2026.6.0b3/esphome/components/nrf52/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · esphome-2026.6.0b3/esphome/components/rp2040/__init__.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · esphome-2026.6.0b3/esphome/dashboard/web_server.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · esphome-2026.6.0b3/esphome/components/dashboard_import/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · esphome-2026.6.0b3/esphome/components/esp32/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · esphome-2026.6.0b3/esphome/components/font/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.0b3Review402026-06-16
2026.6.0b2Review402026-06-15
2026.6.0b1Review402026-06-11
2026.5.3Review402026-06-05
2026.5.2Review402026-06-02

Block this in CI

PkgRadar gates esphome (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi esphome==2026.6.0b3