PkgRadar

PyPI · pypi.org

hikyuu

Py Import Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Why PkgRadar flagged 2.8.0

SeveritySignalEvidence
highPy Import Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · hikyuu/__init__.py
mediumPy Import Time Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · hikyuu/__init__.py
mediumLarge Native Blob6541200 bytes · hikyuu/cpp/core310.so
mediumLarge Native Blob6541264 bytes · hikyuu/cpp/core311.so
mediumLarge Native Blob6623472 bytes · hikyuu/cpp/core312.so
mediumLarge Native Blob6623664 bytes · hikyuu/cpp/core313.so
mediumLarge Native Blob6672944 bytes · hikyuu/cpp/core314.so
mediumLarge Native Blob36617984 bytes · hikyuu/cpp/libhikyuu.dylib
mediumLarge Native Blob7579312 bytes · hikyuu/cpp/libmysqlclient.21.dylib
mediumLarge Native Blob7579344 bytes · hikyuu/cpp/libmysqlclient.dylib
mediumLarge Native Blob7779704 bytes · hikyuu/plugin/libclickhousedriver.dylib
mediumLarge Native Blob7235008 bytes · hikyuu/plugin/libdataserver.dylib

Scanned versions

VersionVerdictScoreScanned (UTC)
2.8.0High risk1212026-06-10

Block this in CI

PkgRadar gates hikyuu (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi hikyuu==2.8.0