PkgRadar

PyPI · pypi.org

planemo

Py Runtime Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 0.75.44

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · planemo-0.75.44/planemo/tool_builder.py
mediumPy Runtime Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · planemo-0.75.44/planemo/xml/validation.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · planemo-0.75.44/planemo/database/postgres_singularity.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · planemo-0.75.44/planemo/io.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · planemo-0.75.44/planemo/shed2tap/base.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · planemo-0.75.44/planemo/autopygen/argument_parser_conversion.py
mediumRemote Payloadmatched "github.com/natefoo/slurm-drmaa/releases/download" · planemo-0.75.44/planemo/commands/cmd_slurm_init.py
mediumRemote Payloadmatched "github.com/cli/cli/releases/download" · planemo-0.75.44/planemo/github_util.py
mediumObfuscation Densityhigh encoded/escaped-token density · planemo-0.75.44/planemo/reports/markdown-it.min.js
mediumRemote Payloadmatched "curl " · planemo-0.75.44/planemo/shed2tap/base.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.75.44Review502026-05-26

Block this in CI

PkgRadar gates planemo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi planemo==0.75.44