PkgRadar

PyPI · pypi.org

sovereign-inference

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.2.10

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · sovereign_inference-0.2.10/_skbuild/win-amd64-3.11/cmake-build/_deps/pybind11-src/setup.py
mediumPy Install Time Eval ExecPython eval()/exec() called on a string. · sovereign_inference-0.2.10/_skbuild/win-amd64-3.11/cmake-build/_deps/pybind11-src/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.10Review952026-05-30
0.2.9Review952026-05-30
0.2.8Review122026-05-27
0.2.7Review122026-05-27
0.2.6Review122026-05-27
0.2.5Review122026-05-27
0.2.4Review122026-05-27
0.2.3Review122026-05-27
0.2.2Review122026-05-27
0.2.1Review122026-05-27
0.2.0Review122026-05-27
0.1.0Review122026-05-27

Block this in CI

PkgRadar gates sovereign-inference (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi sovereign-inference==0.2.10