PyPI · pypi.org
localcode
Py Install Time Subprocess: subprocess call — process spawning.
Why PkgRadar flagged 0.2.12.1a1
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Subprocess | subprocess call — process spawning. · localcode-0.2.12.1a1/src/localcode/tui/screens/setup.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · localcode-0.2.12.1a1/src/localcode/tools/bash.py |
| high | Py Install Time Network Call | Network call (urllib/requests/httpx/http.client) at install or import time. · localcode-0.2.12.1a1/src/localcode/tui/screens/setup.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.2.12.1a1 | High risk | 131 | 2026-06-09 |
Block this in CI
pkgradar gate --ecosystem pypi localcode==0.2.12.1a1