PkgRadar

PyPI · pypi.org

pyglove

Py Install Time Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 0.5.0.dev202606170947

SeveritySignalEvidence
mediumPy Install Time Eval ExecPython eval()/exec() called on a string. · pyglove-0.5.0.dev202606170947/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.0.dev202606170947Review222026-06-17
0.5.0.dev202606160955Review222026-06-16
0.5.0.dev202606151017Review222026-06-15
0.5.0.dev202606140915Review222026-06-14
0.5.0.dev202606130913Review222026-06-13
0.5.0.dev202606120935Review222026-06-12
0.5.0.dev202606110940Review222026-06-11
0.5.0.dev202606100926Review222026-06-10
0.5.0.dev202606090920Review222026-06-09
0.5.0.dev202606080947Review222026-06-08
0.5.0.dev202606070912Review222026-06-07
0.5.0.dev202606060902Review222026-06-06
0.5.0.dev202606050920Review222026-06-05
0.5.0.dev202606040930Review222026-06-04
0.5.0.dev202606030947Review222026-06-03
0.5.0.dev202606020939Review222026-06-02
0.5.0.dev202606011000Review222026-06-01
0.5.0.dev202605310912Review222026-05-31
0.5.0.dev202605300856Review222026-05-30
0.5.0.dev202605290922Review222026-05-29
0.5.0.dev202605280927Review222026-05-28
0.5.0.dev202605270921Review222026-05-27

Block this in CI

PkgRadar gates pyglove (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pyglove==0.5.0.dev202606170947