PkgRadar

PyPI · pypi.org

policyengine-taxsim

Py Runtime Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 2.21.10

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · policyengine_taxsim-2.21.10/policyengine_taxsim/runners/taxsim_runner.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.26.1Low risk02026-06-04
2.26.0Low risk02026-06-04
2.25.1Low risk02026-06-04
2.25.0Low risk02026-06-03
2.24.0Low risk02026-06-02
2.23.1Low risk02026-06-02
2.23.0Low risk02026-05-29
2.22.0Low risk02026-05-28
2.21.12Low risk02026-05-28
2.21.11Low risk02026-05-27
2.21.10Review302026-05-26

Block this in CI

PkgRadar gates policyengine-taxsim (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi policyengine-taxsim==2.21.10