PkgRadar

PyPI · pypi.org

latch

Credential File Packaged: latch-2.76.0/src/latch_cli/services/init/assemble_and_sort/.env

Why PkgRadar flagged 2.76.0

SeveritySignalEvidence
highCredential File Packagedlatch-2.76.0/src/latch_cli/services/init/assemble_and_sort/.env · latch-2.76.0/src/latch_cli/services/init/assemble_and_sort/.env
mediumPy Import Time Subprocesssubprocess call — process spawning. · latch-2.76.0/src/latch_cli/utils/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.76.0High risk482026-06-05
2.75.0High risk482026-06-05

Block this in CI

PkgRadar gates latch (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi latch==2.76.0