PkgRadar

PyPI · pypi.org

vibephysics

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.4.2

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · vibephysics-0.4.2/src/vibephysics/feedforward/lingbot_map/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · vibephysics-0.4.2/src/vibephysics/feedforward/map_anything/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.2Review502026-06-02
0.4.1Review502026-06-02
0.4.0Review502026-06-02
0.3.7Review502026-05-31
0.3.6Review502026-05-31
0.3.5Review502026-05-31
0.3.4Review502026-05-30
0.3.3Review502026-05-30

Block this in CI

PkgRadar gates vibephysics (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi vibephysics==0.4.2