PkgRadar

PyPI · pypi.org

pioreactor

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 26.5.3

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · pioreactor/cluster_management/__init__.py
mediumRemote Payloadmatched "wget " · pioreactor/cli/pio.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · pioreactor/web/static/static/js/196.7f59f848.chunk.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · pioreactor/web/static/static/js/446.b6f5fa5a.chunk.js

Scanned versions

VersionVerdictScoreScanned (UTC)
26.5.3Review202026-06-03
26.5.3rc2Review202026-06-03
26.5.3rc0Review202026-06-01

Block this in CI

PkgRadar gates pioreactor (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pioreactor==26.5.3