PyPI · pypi.org
liger-kernel-nightly
Py Install Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.
Why PkgRadar flagged 0.8.0.dev20260611145756
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Subprocess | subprocess call with shell=True — passes argv to /bin/sh. · liger_kernel_nightly-0.8.0.dev20260611145756/setup.py |
| medium | Py Install Time Subprocess | subprocess call — process spawning. · liger_kernel_nightly-0.8.0.dev20260611145756/setup.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.8.0.dev20260611145756 | Review | 50 | 2026-06-11 |
0.8.0.dev20260611145605 | Review | 50 | 2026-06-11 |
0.8.0.dev20260610212417 | Review | 50 | 2026-06-10 |
0.8.0.dev20260610205228 | Review | 50 | 2026-06-10 |
0.8.0.dev20260609202624 | Review | 50 | 2026-06-09 |
0.8.0.dev20260605180032 | Review | 50 | 2026-06-05 |
0.8.0.dev20260605175131 | Review | 50 | 2026-06-05 |
0.8.0.dev20260604160932 | Review | 50 | 2026-06-04 |
0.8.0.dev20260604160620 | Review | 50 | 2026-06-04 |
0.8.0.dev20260604153053 | Review | 50 | 2026-06-04 |
0.8.0.dev20260601200337 | Review | 50 | 2026-06-01 |
0.8.0.dev20260528004734 | Review | 50 | 2026-05-30 |
0.8.0.dev20260527233919 | Review | 50 | 2026-05-30 |
0.8.0.dev20260526211009 | Review | 50 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi liger-kernel-nightly==0.8.0.dev20260611145756