PkgRadar

PyPI · pypi.org

vespacli

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 8.707.16

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · vespacli-8.707.16/vespacli/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
8.707.16Review162026-06-17
8.703.17Review162026-06-10
8.702.91Review162026-06-09
8.700.24Review162026-06-08
8.699.8Review162026-06-03
8.696.20Review162026-06-01
8.695.32Review242026-05-28
8.694.53Review242026-05-27

Block this in CI

PkgRadar gates vespacli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi vespacli==8.707.16