PkgRadar

PyPI · pypi.org

pebble-tool

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 5.0.38

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · pebble_tool-5.0.38/pebble_tool/commands/sdk/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · pebble_tool-5.0.38/pebble_tool/commands/sdk/project/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.38Review352026-06-11
5.0.37Review352026-06-04
5.0.36Review352026-06-03

Block this in CI

PkgRadar gates pebble-tool (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pebble-tool==5.0.38