PkgRadar

PyPI · pypi.org

tensorcircuit-nightly

Py Runtime Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 1.6.0.dev20260526

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call — process spawning. · tensorcircuit_nightly-1.6.0.dev20260526/tensorcircuit/vis.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · tensorcircuit_nightly-1.6.0.dev20260526/tensorcircuit/compiler/qiskit_compiler.py
mediumPy Runtime Pickle Loadspickle/marshal.loads — deserializes arbitrary objects, RCE if attacker-controlled. · tensorcircuit_nightly-1.6.0.dev20260526/tensorcircuit/experimental.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.0.dev20260612Low risk02026-06-12
1.6.0.dev20260611Low risk02026-06-11
1.6.0.dev20260610Low risk02026-06-10
1.6.0.dev20260609Low risk02026-06-09
1.6.0.dev20260608Low risk02026-06-08
1.6.0.dev20260607Low risk02026-06-07
1.6.0.dev20260606Low risk02026-06-06
1.6.0.dev20260605Low risk02026-06-05
1.6.0.dev20260604Low risk02026-06-04
1.6.0.dev20260603Low risk02026-06-03
1.6.0.dev20260602Low risk02026-06-02
1.6.0.dev20260601Low risk02026-06-01
1.6.0.dev20260531Low risk02026-05-31
1.6.0.dev20260530Low risk02026-05-30
1.6.0.dev20260529Low risk02026-05-29
1.6.0.dev20260528Low risk02026-05-28
1.6.0.dev20260526Review272026-05-26

Block this in CI

PkgRadar gates tensorcircuit-nightly (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi tensorcircuit-nightly==1.6.0.dev20260526