PkgRadar

PyPI · pypi.org

girder-slicer-cli-web

Py Runtime Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 5.0.9

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · girder_slicer_cli_web-5.0.9/slicer_cli_web/worker_tools.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · girder_slicer_cli_web-5.0.9/example-average-color/cli_list.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · girder_slicer_cli_web-5.0.9/example-girder-requests/cli_list.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · girder_slicer_cli_web-5.0.9/slicer_cli_web/cli_list_entrypoint.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · girder_slicer_cli_web-5.0.9/slicer_cli_web/upload_slicer_cli_task.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · girder_slicer_cli_web-5.0.9/small-docker/cli_list.py

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.11.dev11Low risk02026-06-10
5.0.11.dev9Low risk02026-06-09
5.0.11.dev7Low risk02026-06-09
5.0.11.dev4Low risk02026-06-02
5.0.11.dev2Low risk02026-06-02
5.0.10Low risk02026-06-02
5.0.10.dev8Low risk02026-06-01
5.0.10.dev6Low risk02026-06-01
5.0.10.dev4Low risk02026-06-01
5.0.10.dev2Low risk02026-06-01
5.0.9Review252026-05-26
5.0.9.dev4Review252026-05-26

Block this in CI

PkgRadar gates girder-slicer-cli-web (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi girder-slicer-cli-web==5.0.9