PkgRadar

PyPI · pypi.org

safety

Py Runtime Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 3.8.0

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/cli_util.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/util.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/events/utils/emission.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/scan/util.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/tool/base.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/tool/resolver.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/tool/interceptors/windows.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/tool/npm/main.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/tool/pip/main.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/tool/poetry/main.py
mediumPy Runtime Subprocesssubprocess call — process spawning. · safety-3.8.0/safety/utils/machine_id.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.8.1Low risk02026-05-29
3.8.0Review152026-05-26
3.8.0b4Review152026-05-26

Block this in CI

PkgRadar gates safety (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi safety==3.8.0