PkgRadar

PyPI · pypi.org

khy-os

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.1.100

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · khy_os-0.1.100/setup.py
highCredential File Packagedkhy_os-0.1.100/services/backend/.npmrc · khy_os-0.1.100/services/backend/.npmrc
mediumRemote Payloadmatched "curl " · khy_os-0.1.100/services/backend/src/services/cliAnythingService.js
mediumRemote Payloadmatched "curl " · khy_os-0.1.100/services/backend/src/services/knowledgeTeachingService.js
mediumCredential file accessmatched ".pypirc" · khy_os-0.1.100/services/backend/src/cli/handlers/publish.js
mediumCredential file accessmatched ".npmrc" · khy_os-0.1.100/software/khyquant/khy_quant/_bootstrap.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.100High risk1542026-06-13
0.1.99High risk1542026-06-13
0.1.98High risk1542026-06-12
0.1.97High risk1542026-06-12
0.1.96High risk1542026-06-11
0.1.95High risk1542026-06-11
0.1.94High risk1542026-06-10
0.1.92High risk1592026-06-08
0.1.91High risk1492026-06-05
0.1.90High risk1492026-06-05
0.1.89High risk1492026-06-05
0.1.88High risk1492026-06-03
0.1.87High risk1492026-06-03
0.1.86High risk1492026-06-02
0.1.85High risk1492026-06-02
0.1.84High risk1492026-06-02
0.1.83High risk1492026-06-02
0.1.82High risk1492026-06-01
0.1.81High risk1492026-06-01
0.1.80High risk1492026-06-01
0.1.79High risk1492026-05-31
0.1.78High risk1492026-05-30
0.1.77High risk1492026-05-30
0.1.76High risk1392026-05-30
0.1.75High risk1392026-05-30
0.1.73High risk1392026-05-30
0.1.72High risk1392026-05-30
0.1.71High risk1392026-05-30
0.1.70High risk1392026-05-30
0.1.69High risk1392026-05-30
0.1.68High risk1292026-05-30
0.1.67High risk1292026-05-30
0.1.66High risk1292026-05-30
0.1.65High risk1292026-05-30
0.1.64High risk1292026-05-30
0.1.63High risk1292026-05-30
0.1.62High risk1292026-05-30
0.1.61High risk1292026-05-30
0.1.60High risk1292026-05-30
0.1.59High risk1292026-05-30
0.1.58High risk1292026-05-30
0.1.57High risk1172026-05-30
0.1.56High risk1172026-05-30

Block this in CI

PkgRadar gates khy-os (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi khy-os==0.1.100