PyPI · pypi.org
proot-distro
Py Import Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.
Why PkgRadar flagged 5.2.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Import Time Os System | Direct shell invocation via os.system / os.popen / os.exec*. · proot_distro-5.2.0/proot_distro/commands/login/__init__.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
5.2.0 | High risk | 55 | 2026-06-11 |
5.1.7 | High risk | 55 | 2026-06-09 |
5.1.6 | High risk | 55 | 2026-06-09 |
5.1.5 | High risk | 55 | 2026-06-07 |
5.1.4 | High risk | 55 | 2026-06-01 |
5.1.3 | High risk | 55 | 2026-05-31 |
5.1.2 | High risk | 55 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi proot-distro==5.2.0