PkgRadar

PyPI · pypi.org

jarv

Py Install Time Network Call: Network call (urllib/requests/httpx/http.client) at install or import time.

Why PkgRadar flagged 0.33.0

SeveritySignalEvidence
highPy Install Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · jarv-0.33.0/jarv/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.33.0High risk362026-06-17
0.32.0High risk362026-06-17
0.31.3High risk362026-06-16
0.31.2High risk362026-06-16
0.31.1High risk362026-06-15
0.31.0High risk362026-06-15
0.30.0High risk362026-06-15
0.29.0High risk362026-06-15
0.28.2High risk362026-06-14
0.28.1High risk362026-06-14
0.28.0High risk362026-06-14
0.27.0High risk362026-06-13
0.26.0High risk362026-06-13
0.25.1High risk362026-06-13
0.25.0High risk362026-06-12
0.24.2High risk362026-06-12
0.24.1High risk362026-06-12
0.24.0High risk362026-06-11
0.23.2High risk362026-06-11
0.21.0High risk362026-06-10
0.20.0High risk362026-06-10
0.19.0High risk362026-06-10
0.18.0High risk362026-06-10
0.17.0High risk362026-06-08
0.16.0High risk362026-06-06
0.15.2High risk362026-06-06
0.15.1High risk362026-06-06
0.15.0High risk362026-06-06
0.14.1High risk362026-06-03
0.14.0High risk362026-06-03
0.13.1High risk362026-06-03
0.13.0High risk362026-06-01
0.12.1High risk362026-05-30
0.12.0High risk362026-05-30
0.11.1High risk362026-05-30
0.11.0High risk362026-05-30
0.10.7High risk362026-05-30
0.10.6High risk362026-05-30

Block this in CI

PkgRadar gates jarv (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi jarv==0.33.0