PkgRadar

PyPI · pypi.org

flash-attn

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 2.8.3.post1

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · flash_attn-2.8.3.post1/csrc/fused_dense_lib/setup.py
mediumPy Install Time Subprocesssubprocess call — process spawning. · flash_attn-2.8.3.post1/csrc/layer_norm/setup.py
mediumPy Install Time Subprocesssubprocess call — process spawning. · flash_attn-2.8.3.post1/hopper/setup.py
mediumPy Install Time Subprocesssubprocess call — process spawning. · flash_attn-2.8.3.post1/setup.py
highPy Install Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · flash_attn-2.8.3.post1/hopper/setup.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · flash_attn-2.8.3.post1/csrc/cutlass/python/cutlass/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.8.3.post1High risk592026-06-11

Block this in CI

PkgRadar gates flash-attn (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi flash-attn==2.8.3.post1