PkgRadar

PyPI · pypi.org

synapse-orch-ai

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 1.7.6

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · synapse_orch_ai-1.7.6/setup.py
mediumRemote Payloadmatched "curl " · synapse_orch_ai-1.7.6/setup.py
mediumRemote Payloadmatched "curl " · synapse_orch_ai-1.7.6/setup.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.7.6Review1192026-06-11
1.7.5Review1192026-06-11
1.7.4Review1192026-06-11
1.7.3Review1192026-06-10
1.7.2Review1192026-06-08
1.7.1Review1192026-06-08
1.7.0Review1192026-06-05
1.6.6Review1042026-05-30

Block this in CI

PkgRadar gates synapse-orch-ai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi synapse-orch-ai==1.7.6