PkgRadar

PyPI · pypi.org

visionservex

Py Runtime Dynamic Dangerous Import: Dynamic __import__('sys') — reflection bypass for static checks.

Why PkgRadar flagged 3.11.0

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · visionservex-3.11.0/src/visionservex/cli/gpu_commands.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · visionservex-3.11.0/src/visionservex/cli/maskdino_commands.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · visionservex-3.11.0/src/visionservex/engines/florence2.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.11.0High risk802026-06-08
3.10.1High risk802026-06-08
3.10.0High risk802026-06-08
3.9.1High risk802026-06-08
3.9.0High risk802026-06-08
3.8.1High risk802026-06-08
3.8.0High risk802026-06-08
3.7.0High risk802026-06-07
3.3.0High risk802026-06-07
3.2.0High risk802026-06-07
3.1.0High risk802026-06-07
3.0.0High risk802026-06-07
2.60.0High risk802026-06-07
2.59.0High risk802026-06-07

Block this in CI

PkgRadar gates visionservex (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi visionservex==3.11.0