PkgRadar

PyPI · pypi.org

evolver-tools

Py Import Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 38.0.25

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · evolver_tools-38.0.25/src/evolver_tools/vendor/ff/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · evolver_tools-38.0.25/src/evolver_tools/vendor/project_doctor/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
38.0.25Review802026-06-01
38.0.24Review802026-06-01
38.0.23Review802026-06-01
38.0.22Review802026-06-01
38.0.21Review802026-06-01
38.0.20Review802026-06-01
38.0.19Review802026-06-01
38.0.18Review802026-06-01
38.0.17Review802026-06-01
38.0.16Review802026-06-01
38.0.15Review802026-06-01
38.0.14Review802026-06-01
38.0.13Review802026-06-01
38.0.12Review802026-06-01
38.0.11Review802026-06-01
38.0.10Review802026-06-01
38.0.9Review802026-05-31
38.0.8Review802026-05-31
38.0.7Review802026-05-31
38.0.6Review802026-05-31
38.0.5Review802026-05-31
38.0.4Review802026-05-31
38.0.3Review802026-05-31
38.0.2Review802026-05-31
38.0.1Review802026-05-31
38.0.0Review802026-05-31
37.0.0Review802026-05-31
36.0.0Review802026-05-31
35.0.0Review802026-05-31
34.0.0Review802026-05-31
33.0.0Review802026-05-31
32.0.0Review802026-05-31
31.0.0Review802026-05-31
30.0.0Review802026-05-31
29.0.0Review802026-05-31
28.0.0Review802026-05-31
27.0.1Review802026-05-31
27.0.0Review802026-05-31
25.0.0Review802026-05-31
24.0.0Review802026-05-31
23.0.0Review802026-05-31
22.0.0Review802026-05-31
21.0.0Review802026-05-31
20.0.0Review802026-05-31
19.0.0Review802026-05-31
18.0.0Review802026-05-31
17.0.0Review802026-05-31
16.0.0Review802026-05-31
15.0.0Review802026-05-31
14.0.0Review802026-05-30
13.0.0Review802026-05-30
12.0.0Review802026-05-30
11.0.0Review802026-05-30
5.0.0Review802026-05-30
10.0.0Review982026-05-30
3.1.0Review802026-05-30
3.0.0Review802026-05-30
2.5.0Review802026-05-30
2.4.0Review802026-05-30
2.3.0Review802026-05-30
2.2.0Review802026-05-30
2.1.0Review802026-05-30
2.0.0Review802026-05-30
1.5.0Review802026-05-30
1.4.0Review802026-05-30

Block this in CI

PkgRadar gates evolver-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi evolver-tools==38.0.25