PyPI · pypi.org
jd-worker
Py Runtime Dynamic Dangerous Import: Dynamic __import__('subprocess') — reflection bypass for static checks.
Why PkgRadar flagged 1.20.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('subprocess') — reflection bypass for static checks. · jd_worker-1.20.0/jd/worker_commands.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.20.0 | High risk | 30 | 2026-06-14 |
1.19.0 | High risk | 30 | 2026-06-14 |
1.18.0 | High risk | 30 | 2026-06-14 |
1.16.0 | High risk | 30 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi jd-worker==1.20.0