PkgRadar

PyPI · pypi.org

scitex-io

Py Runtime Dynamic Dangerous Import: Dynamic __import__('sys') — reflection bypass for static checks.

Why PkgRadar flagged 0.3.1

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · scitex_io-0.3.1/src/scitex_io/_save.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.1High risk302026-06-06
0.3.0High risk302026-06-06
0.2.21High risk302026-06-05
0.2.20High risk302026-06-01
0.2.19High risk302026-05-30
0.2.18High risk302026-05-30
0.2.17High risk302026-05-30
0.2.16High risk302026-05-30

Block this in CI

PkgRadar gates scitex-io (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi scitex-io==0.3.1