PkgRadar

PyPI · pypi.org

rekipedia

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 0.24.0

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · rekipedia-0.24.0/src/rekipedia/orchestrator/run_digest.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.24.0High risk302026-06-15
0.23.1High risk302026-06-14
0.23.0High risk302026-06-13
0.22.1High risk302026-06-11
0.22.0High risk302026-06-08
0.21.2High risk302026-06-04
0.21.1High risk302026-06-03
0.20.0High risk302026-06-01
0.17.27High risk302026-05-30
0.17.30High risk302026-05-30
0.17.29High risk302026-05-30
0.17.28High risk302026-05-30

Block this in CI

PkgRadar gates rekipedia (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi rekipedia==0.24.0