PkgRadar

PyPI · pypi.org

specfact-cli

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 0.47.11

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · specfact_cli-0.47.11/src/specfact_cli/registry/bootstrap.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.47.11High risk282026-06-14
0.47.6High risk282026-06-12
0.47.3High risk282026-06-02

Block this in CI

PkgRadar gates specfact-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi specfact-cli==0.47.11
specfact-cli — PyPI security scan | PkgRadar