PyPI · pypi.org
ultralytics
Py Import Time Subprocess: subprocess call — process spawning.
Why PkgRadar flagged 8.4.70
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Import Time Subprocess | subprocess call — process spawning. · ultralytics-8.4.70/ultralytics/cfg/__init__.py |
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('sys') — reflection bypass for static checks. · ultralytics-8.4.70/ultralytics/engine/tuner.py |
| high | Py Import Time Network Call | Network call (urllib/requests/httpx/http.client) at install or import time. · ultralytics-8.4.70/ultralytics/hub/__init__.py |
| high | Py Import Time Network Call | Network call (urllib/requests/httpx/http.client) at install or import time. · ultralytics-8.4.70/ultralytics/hub/google/__init__.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
8.4.70 | High risk | 47 | 2026-06-17 |
8.4.69 | High risk | 47 | 2026-06-16 |
8.4.68 | High risk | 47 | 2026-06-15 |
8.4.67 | High risk | 47 | 2026-06-14 |
8.4.66 | High risk | 47 | 2026-06-11 |
8.4.65 | High risk | 47 | 2026-06-11 |
8.4.64 | High risk | 47 | 2026-06-10 |
8.4.63 | High risk | 47 | 2026-06-09 |
8.4.62 | High risk | 47 | 2026-06-08 |
8.4.61 | High risk | 47 | 2026-06-07 |
8.4.60 | High risk | 47 | 2026-06-01 |
8.4.59 | High risk | 47 | 2026-06-01 |
8.4.58 | High risk | 47 | 2026-05-31 |
8.4.57 | High risk | 47 | 2026-05-30 |
8.4.56 | High risk | 47 | 2026-05-30 |
8.4.55 | High risk | 47 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi ultralytics==8.4.70