PkgRadar

PyPI · pypi.org

supervisely

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 6.74.0

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · supervisely-6.74.0/setup.py
highPy Install Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · supervisely-6.74.0/setup.py
mediumRemote Payloadmatched "curl " · supervisely-6.74.0/supervisely/app/development/sly-net.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
6.74.0Review292026-06-12
6.73.582Review292026-06-11
6.73.581Review292026-06-10
6.73.580Review292026-06-02
6.73.579Review292026-06-01
6.73.578Review292026-05-29
6.73.577Review292026-05-29
6.73.576Review322026-05-28
6.73.575Review322026-05-28
6.73.574Review392026-05-27

Block this in CI

PkgRadar gates supervisely (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi supervisely==6.74.0