PkgRadar

PyPI · pypi.org

girder-large-image

Py Runtime Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 1.34.2.dev20

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call — process spawning. · girder_large_image-1.34.2.dev20/test_girder/conftest.py
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · girder_large_image-1.34.2.dev20/girder_large_image/models/image_item.py
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · girder_large_image-1.34.2.dev20/test_girder/test_tiles_rest.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.34.3.dev4Low risk02026-06-04
1.34.3.dev2Low risk02026-06-04
1.34.2Low risk02026-06-02
1.34.3a171Low risk02026-06-02
1.34.2.dev28Low risk02026-06-01
1.34.2.dev26Low risk02026-06-01
1.34.2.dev24Low risk02026-05-28
1.34.2.dev22Low risk02026-05-28
1.34.2.dev20Review162026-05-26

Block this in CI

PkgRadar gates girder-large-image (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi girder-large-image==1.34.2.dev20