PkgRadar

PyPI · pypi.org

polyaxon

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 2.16.1

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · polyaxon-2.16.1/polyaxon/_ssh/setup.py
mediumCredential file accessmatched "id_rsa" · polyaxon-2.16.1/polyaxon/_init/git.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.16.1Review192026-05-29
2.16.0Review192026-05-29

Block this in CI

PkgRadar gates polyaxon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi polyaxon==2.16.1