PyPI · pypi.org
torchani
Py Install Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.
Why PkgRadar flagged 2.8.2
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Subprocess | subprocess call with shell=True — passes argv to /bin/sh. · torchani-2.8.2/setup.py |
| medium | Remote Payload | matched "wget " · torchani-2.8.2/download-dev-data.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.8.2 | Review | 31 | 2026-05-28 |
2.8.1 | Review | 31 | 2026-05-28 |
Block this in CI
pkgradar gate --ecosystem pypi torchani==2.8.2