PkgRadar

PyPI · pypi.org

glsmei

Py Install Time Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 1.0.6

SeveritySignalEvidence
mediumPy Install Time Eval ExecPython eval()/exec() called on a string. · glsmei-1.0.6/_skbuild/win-amd64-3.11/cmake-install/setup.py
mediumPy Install Time Eval ExecPython eval()/exec() called on a string. · glsmei-1.0.6/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.6Review502026-06-07
1.0.5Review502026-06-07
1.0.4Review502026-06-07
1.0.3Review502026-06-07
1.0.2Review502026-06-07

Block this in CI

PkgRadar gates glsmei (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi glsmei==1.0.6