PkgRadar

PyPI · pypi.org

session-buddy

Py Runtime Dynamic Dangerous Import: Dynamic __import__('sys') — reflection bypass for static checks.

Why PkgRadar flagged 0.19.12

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · session_buddy-0.19.12/session_buddy/resource_cleanup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.19.12High risk282026-06-12
0.19.11High risk352026-06-05
0.19.10High risk352026-06-04
0.19.9High risk352026-06-03
0.19.8High risk352026-06-02
0.19.7High risk352026-05-31
0.19.6High risk352026-05-31
0.19.5High risk352026-05-31
0.19.4High risk352026-05-30
0.19.3High risk352026-05-30

Block this in CI

PkgRadar gates session-buddy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi session-buddy==0.19.12