PkgRadar

PyPI · pypi.org

girder-large-image-annotation

Py Runtime Pickle Loads: pickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled.

Why PkgRadar flagged 1.34.2.dev20

SeveritySignalEvidence
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · girder_large_image_annotation-1.34.2.dev20/girder_large_image_annotation/models/annotationelement.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.34.3.dev4Low risk02026-06-04
1.34.3.dev2Low risk02026-06-04
1.34.3a171Low risk02026-06-02
1.34.2Low risk02026-06-02
1.34.2.dev28Low risk02026-06-01
1.34.2.dev26Low risk02026-06-01
1.34.2.dev24Low risk02026-05-28
1.34.2.dev22Low risk02026-05-28
1.34.2.dev20Review72026-05-26

Block this in CI

PkgRadar gates girder-large-image-annotation (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi girder-large-image-annotation==1.34.2.dev20