PkgRadar

PyPI · pypi.org

ligo-skymap

Py Import Time Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 2.5.5.dev2

SeveritySignalEvidence
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · ligo_skymap-2.5.5.dev2/ligo/skymap/coordinates/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · ligo_skymap-2.5.5.dev2/ligo/skymap/io/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · ligo_skymap-2.5.5.dev2/ligo/skymap/io/events/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · ligo_skymap-2.5.5.dev2/ligo/skymap/plot/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · ligo_skymap-2.5.5.dev2/ligo/skymap/postprocess/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · ligo_skymap-2.5.5.dev2/ligo/skymap/util/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.5.dev2Review152026-06-13
2.5.5.dev1Review152026-06-07
2.5.4Review152026-06-06
2.5.4.dev8Review152026-06-06
2.5.4.dev4Review152026-05-28
2.5.4.dev3Review152026-05-27

Block this in CI

PkgRadar gates ligo-skymap (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ligo-skymap==2.5.5.dev2