PyPI · pypi.org
gbp
Py Install Time Eval Exec: Python eval()/exec() called on a string.
Why PkgRadar flagged 0.9.43
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Eval Exec | Python eval()/exec() called on a string. · gbp-0.9.43/setup.py |
| medium | Py Import Time Subprocess | subprocess call — process spawning. · gbp-0.9.43/gbp/deb/__init__.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.9.43 | Review | 38 | 2026-05-28 |
Block this in CI
pkgradar gate --ecosystem pypi gbp==0.9.43