PkgRadar

PyPI · pypi.org

merobox

Py Runtime Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.6.19

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call — process spawning. · merobox-0.6.19/merobox/commands/binary_manager.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · merobox-0.6.19/merobox/commands/bootstrap/steps/script.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.36Low risk02026-06-07
0.6.35Low risk02026-06-04
0.6.34Low risk02026-06-03
0.6.33Low risk02026-06-03
0.6.32Low risk02026-05-30
0.6.31Low risk02026-05-30
0.6.30Low risk02026-05-30
0.6.29Low risk02026-05-30
0.6.28Low risk02026-05-29
0.6.27Low risk02026-05-29
0.6.26Low risk02026-05-29
0.6.25Low risk02026-05-28
0.6.24Low risk02026-05-27
0.6.23Low risk02026-05-27
0.6.22Low risk02026-05-27
0.6.21Low risk02026-05-27
0.6.20Low risk02026-05-27
0.6.19Review352026-05-26

Block this in CI

PkgRadar gates merobox (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi merobox==0.6.19