subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
try: print(f" [INFO] 将执行: pip install {pkg_name}(从 PyPI 下载,约数 MB,不会上传本机数据)") print(f" [依赖] 安装 {pkg_name} ...", end='', flush=True) result = subprocess.run( [sys.executable, '-m', 'pip', 'install', pkg_name, '-q'], capture_output=True, text=True, timeout=120, )- Confidence
- 97% confidence
- Finding
- result = subprocess.run( [sys.executable, '-m', 'pip', 'install', pkg_name, '-q'], capture_output=True, text=True, timeout=120, )
