PkgRadar

PyPI · pypi.org

orcheo

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.39.1

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · orcheo-0.39.1/packages/sdk/src/orcheo_sdk/cli/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.39.1Review382026-06-11
0.39.0Review382026-06-10
0.38.4Review382026-06-10
0.38.3Review382026-06-07
0.38.2Review382026-06-06
0.38.1Review382026-06-06
0.38.0Review382026-06-06
0.37.4Review422026-06-05
0.37.3Review422026-06-05
0.37.2Review422026-06-05
0.37.1Review422026-06-04
0.37.0Review422026-06-03

Block this in CI

PkgRadar gates orcheo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi orcheo==0.39.1