PkgRadar

PyPI · pypi.org

litellm

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 1.84.9

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · litellm-1.84.9/litellm/integrations/gcs_bucket/gcs_bucket_mock_client.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · litellm-1.84.9/litellm/llms/vertex_ai/image_edit/vertex_gemini_transformation.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · litellm-1.84.9/litellm/llms/vertex_ai/image_edit/vertex_imagen_transformation.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · litellm-1.84.9/litellm/llms/vertex_ai/image_generation/vertex_gemini_transformation.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · litellm-1.84.9/litellm/llms/vertex_ai/image_generation/vertex_imagen_transformation.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · litellm-1.84.9/litellm/utils.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.84.9High risk722026-06-17
1.89.1High risk722026-06-16
1.88.2High risk722026-06-14
1.87.3High risk722026-06-14
1.86.6High risk722026-06-14
1.85.6High risk722026-06-14
1.89.0High risk722026-06-13
1.84.8High risk722026-06-13
1.87.2High risk722026-06-11
1.86.5High risk722026-06-11
1.85.5High risk722026-06-11
1.84.7High risk722026-06-11
1.89.0rc2High risk722026-06-10
1.84.6High risk722026-06-09
1.88.1High risk722026-06-09
1.88.0High risk722026-06-06
1.89.0rc1High risk722026-06-06
1.88.0rc3High risk722026-06-05
1.88.0rc2High risk722026-06-04
1.87.1High risk722026-06-04
1.86.4High risk722026-06-04
1.85.4High risk722026-06-04
1.84.5High risk722026-06-04
1.86.3High risk722026-06-03
1.87.0High risk722026-06-02
1.85.3High risk722026-06-02
1.88.0rc1High risk922026-05-31
1.84.4High risk922026-05-31
1.88.0.dev1High risk722026-05-30
1.84.3High risk722026-05-30
1.86.2High risk722026-05-30
1.85.2High risk722026-05-30
1.84.2High risk722026-05-30
1.87.0rc2High risk722026-05-30

Block this in CI

PkgRadar gates litellm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi litellm==1.84.9