PkgRadar

PyPI · pypi.org

mlx-optiq

Py Runtime Dynamic Dangerous Import: Dynamic __import__('sys') — reflection bypass for static checks.

Why PkgRadar flagged 0.2.3

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · mlx_optiq-0.2.3/optiq/runtime/kv/rotating.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.3High risk302026-06-13
0.2.2High risk302026-06-10
0.2.1High risk302026-06-09
0.2.0High risk302026-06-07
0.1.5High risk302026-06-04
0.1.4High risk302026-06-01
0.1.3High risk302026-05-31
0.1.2Low risk02026-05-29
0.1.1Review412026-05-27

Block this in CI

PkgRadar gates mlx-optiq (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi mlx-optiq==0.2.3