PkgRadar

PyPI · pypi.org

getdango

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 1.0.4

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · getdango-1.0.4/dango/transformation/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · getdango-1.0.4/dango/ingestion/dlt_sources/jira/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · getdango-1.0.4/dango/ingestion/dlt_sources/mux/__init__.py
mediumCredential file accessmatched "aws_access_key" · getdango-1.0.4/dango/platform/cloud/migrate.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.4High risk652026-06-15
1.0.3High risk652026-06-11
1.0.2High risk652026-06-08
1.0.1High risk652026-06-07
1.0.0High risk652026-06-07
1.0.0b7High risk652026-06-06
1.0.0b6High risk652026-06-05
1.0.0b5High risk652026-06-05
1.0.0b4High risk652026-06-02
1.0.0b3High risk652026-05-30
1.0.0b2High risk652026-05-30
1.0.0b1High risk652026-05-30

Block this in CI

PkgRadar gates getdango (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi getdango==1.0.4