PkgRadar

PyPI · pypi.org

siliconcompiler

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.37.12

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · siliconcompiler-0.37.12/siliconcompiler/report/dashboard/web/__init__.py
mediumRemote Payloadmatched "wget\n\n" · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel8/install-chisel.sh
mediumRemote Payloadmatched "wget " · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel8/install-icarus.sh
mediumRemote Payloadmatched "wget\n\n" · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel8/install-klayout.sh
mediumRemote Payloadmatched "curl\n" · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel8/install-sv2v.sh
mediumRemote Payloadmatched "wget\n\n" · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel8/install-verible.sh
mediumRemote Payloadmatched "wget\n\n" · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel8/install-verilator.sh
mediumRemote Payloadmatched "wget " · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel8/install-xdm.sh
mediumRemote Payloadmatched "wget\n\n" · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel8/install-xyce.sh
mediumRemote Payloadmatched "wget\n\n" · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel9/install-chisel.sh
mediumRemote Payloadmatched "wget " · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel9/install-gtkwave.sh
mediumRemote Payloadmatched "wget " · siliconcompiler-0.37.12/siliconcompiler/toolscripts/rhel9/install-icarus.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.37.12High risk662026-06-09

Block this in CI

PkgRadar gates siliconcompiler (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi siliconcompiler==0.37.12