PkgRadar

PyPI · pypi.org

olly-desktop

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 1.2.11

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · olly_desktop-1.2.11/core/settings.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · olly_desktop-1.2.11/ui/onboarding_wizard.py
mediumRemote Payloadmatched "curl " · olly_desktop-1.2.11/launch.sh
mediumRemote Payloadmatched "curl " · olly_desktop-1.2.11/core/ollama_setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.11High risk842026-06-11
1.2.10High risk842026-06-11
1.2.9High risk842026-06-11
1.2.8High risk842026-06-10
1.2.7High risk842026-06-10
1.2.6High risk842026-06-10
1.2.5High risk842026-06-10
1.2.4High risk842026-06-10
1.2.3High risk842026-06-10
1.2.2High risk842026-06-10
1.2.1High risk842026-06-10

Block this in CI

PkgRadar gates olly-desktop (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi olly-desktop==1.2.11