PkgRadar

PyPI · pypi.org

virtualenv

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 21.5.1

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · virtualenv-21.5.1/src/virtualenv/util/subprocess/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
21.5.1Review92026-06-16
21.5.0Review92026-06-13
21.4.3Review92026-06-11
21.4.2Review92026-05-31
21.4.1Review92026-05-28
21.4.0Review92026-05-28

Block this in CI

PkgRadar gates virtualenv (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi virtualenv==21.5.1