PyPI · pypi.org
hatchling
Py Import Time Subprocess: subprocess call — process spawning.
Why PkgRadar flagged 1.30.1
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Import Time Subprocess | subprocess call — process spawning. · hatchling-1.30.1/src/hatchling/cli/dep/__init__.py |
| medium | Py Custom Build Backend | Non-standard PEP 517 build-backend `hatchling.ouroboros` — runs custom code at install time. · pyproject.toml |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.30.1 | Review | 23 | 2026-06-02 |
1.30.0 | Review | 23 | 2026-06-01 |
Block this in CI
pkgradar gate --ecosystem pypi hatchling==1.30.1