PyPI · pypi.org
simpletuner
Py Install Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.
Why PkgRadar flagged 4.3.3
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Subprocess | subprocess call with shell=True — passes argv to /bin/sh. · simpletuner-4.3.3/setup.py |
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('socket') — reflection bypass for static checks. · simpletuner-4.3.3/simpletuner/cli/worker.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
4.3.3 | High risk | 87 | 2026-06-07 |
Block this in CI
pkgradar gate --ecosystem pypi simpletuner==4.3.3