PkgRadar

PyPI · pypi.org

powermake

Py Runtime Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 2.13.2

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · powermake-2.13.2/powermake/compilers/asm.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/operation.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/search_visual_studio.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/archivers/gnu.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/archivers/msvc.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/compilers/asm.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/compilers/gnu.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/compilers/msvc.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/linkers/gnu.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/linkers/msvc.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/shared_linkers/gnu.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · powermake-2.13.2/powermake/shared_linkers/msvc.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.14.0Low risk02026-05-31
2.13.2Review402026-05-26

Block this in CI

PkgRadar gates powermake (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi powermake==2.13.2