PkgRadar

PyPI · pypi.org

sogen

Py Install Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Why PkgRadar flagged 0.0.1.dev3928

SeveritySignalEvidence
highPy Install Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · sogen-0.0.1.dev3928/deps/capstone/bindings/python/setup.py
mediumPy Install Time Subprocesssubprocess call — process spawning. · sogen-0.0.1.dev3928/deps/unicorn/bindings/python/setup.py
highCredential File Packagedsogen-0.0.1.dev3928/deps/flatbuffers/.npmrc · sogen-0.0.1.dev3928/deps/flatbuffers/.npmrc
mediumPy Import Time Ctypes Loadctypes.CDLL/cdll.LoadLibrary — loads native code into the process. · sogen-0.0.1.dev3928/deps/capstone/bindings/python/capstone/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.1.dev3928High risk1592026-06-08
0.0.1.dev3926High risk1592026-06-08
0.0.1.dev3924High risk1592026-06-08
0.0.1.dev3919High risk1592026-06-07
0.0.1.dev3917High risk1592026-06-07
0.0.1.dev3911High risk1592026-06-07
0.0.1.dev3905High risk1592026-06-07
0.0.1.dev3880High risk1592026-06-07
0.0.1.dev3878High risk1592026-06-06
0.0.1.dev3875High risk1592026-06-06
0.0.1.dev3870High risk1592026-06-06
0.0.1.dev3869High risk1592026-06-06
0.0.1.dev3860High risk1592026-06-06
0.0.1.dev3858High risk1592026-06-06
0.0.1.dev3819High risk1592026-06-06
0.0.1.dev3815High risk1592026-06-05
0.0.1.dev3814High risk1592026-06-05
0.0.1.dev3810High risk1592026-06-04
0.0.1.dev3808High risk1592026-06-03
0.0.1.dev3796High risk1592026-06-02
0.0.1.dev3774High risk1592026-06-01
0.0.1.dev3748High risk1592026-06-01
0.0.1.dev3742High risk1592026-05-31
0.0.1.dev3731High risk1592026-05-30
0.0.1.dev3727High risk1592026-05-30
0.0.1.dev3706High risk1592026-05-30
0.0.1.dev3740High risk1592026-05-30
0.0.1.dev3701High risk1592026-05-30
0.0.1.dev3696High risk1592026-05-30

Block this in CI

PkgRadar gates sogen (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi sogen==0.0.1.dev3928