PkgRadar

PyPI · pypi.org

vibe-coding-tracker

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.12.0

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · vibe_coding_tracker-0.12.0/src/vibe_coding_tracker/__init__.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.12.0Review322026-06-06
0.11.0Review322026-06-06
0.10.4Review322026-05-30
0.10.3Review322026-05-28

Block this in CI

PkgRadar gates vibe-coding-tracker (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi vibe-coding-tracker==0.12.0