PkgRadar

PyPI · pypi.org

maru-deep-pro-search

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.29.0

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · maru_deep_pro_search-0.29.0/src/maru_deep_pro_search/cli/setup.py
mediumRemote Payloadmatched "curl " · maru_deep_pro_search-0.29.0/src/maru_deep_pro_search/cli/env_check.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.29.0Review622026-06-06
0.28.0Review622026-06-06
0.27.0Review622026-06-05
0.26.14Review622026-05-29

Block this in CI

PkgRadar gates maru-deep-pro-search (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi maru-deep-pro-search==0.29.0