PkgRadar

PyPI · pypi.org

spec-kit-redist

Py Import Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 0.10.2

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · spec_kit_redist-0.10.2/src/specify_cli/workflows/steps/shell/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · spec_kit_redist-0.10.2/src/specify_cli/integrations/copilot/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · spec_kit_redist-0.10.2/src/specify_cli/workflows/steps/prompt/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.2Review982026-06-12
0.10.1Review982026-06-10
0.9.5Review982026-06-06
0.9.4Review982026-06-05
0.9.3Review982026-06-04
0.9.2Review982026-06-03
0.9.0Review982026-06-02
0.8.17Review982026-05-30
0.8.16Review982026-05-30
0.8.14Review982026-05-30
0.8.18Review982026-05-30

Block this in CI

PkgRadar gates spec-kit-redist (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi spec-kit-redist==0.10.2