PkgRadar

PyPI · pypi.org

xtc-tvm-python-bindings

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.19.0.10

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · tvm/3rdparty/cutlass/python/cutlass/__init__.py
mediumLarge Native Blob74836896 bytes · tvm/libtvm.dylib

Scanned versions

VersionVerdictScoreScanned (UTC)
0.19.0.10Review472026-06-03

Block this in CI

PkgRadar gates xtc-tvm-python-bindings (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi xtc-tvm-python-bindings==0.19.0.10