PyPI · pypi.org
scipion-em-eman2
Py Import Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.
Why PkgRadar flagged 3.7.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Import Time Subprocess | subprocess call with shell=True — passes argv to /bin/sh. · scipion_em_eman2-3.7.0/eman2/__init__.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.7.0 | Review | 24 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem pypi scipion-em-eman2==3.7.0