You're Invited:Meet the Socket Team at BlackHat and DEF CON in Las Vegas, Aug 4-6.RSVP →
Socket
Book a DemoInstallSign in
Socket
  • Pricing
  • Love
  • Docs
Book a DemoInstallSign in

scikit-learn

Package Overview
Dependencies
33
Maintainers
8
Alerts
File Explorer

Advanced tools

License
Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install
  1. pypi
  2. scikit-learn
  3. Alerts

scikit-learn - Package Alerts

Shell access

Supply chain risk

This module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.

Found 1 instance in 1 package

Network access

Supply chain risk

This module accesses the network.

Found 1 instance in 1 package

Uses eval

Supply chain risk

Package uses dynamic code execution (e.g., eval()), which is a dangerous practice. This can prevent the code from running in certain environments and increases the risk that the code may contain exploits or malicious behavior.

Found 1 instance in 1 package

URL strings

Supply chain risk

Package contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.

Found 1 instance in 1 package

Environment variable access

Supply chain risk

Package accesses environment variables, which may be a sign of credential stuffing or data theft.

Found 1 instance in 1 package

Filesystem access

Supply chain risk

Accesses the file system, and could potentially read sensitive data.

Found 1 instance in 1 package

Shell access

Supply chain risk

This module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.

Found 627 instances in 627 packages

Network access

Supply chain risk

This module accesses the network.

Found 225 instances in 225 packages

Uses eval

Supply chain risk

Package uses dynamic code execution (e.g., eval()), which is a dangerous practice. This can prevent the code from running in certain environments and increases the risk that the code may contain exploits or malicious behavior.

Found 729 instances in 729 packages

Medium CVE

Vulnerability

Contains a medium severity Common Vulnerability and Exposure (CVE).

Found 12 instances in 4 packages

Native code

Supply chain risk

Contains native code (e.g., compiled binaries or shared libraries). Including native code can obscure malicious behavior.

Found 833 instances in 833 packages

AI-detected possible typosquat

Supply chain risk

There is a package with a similar name that is downloaded much more often.

Did you mean

ninja

Unpopular package

Quality

This package is not very popular.

Found 2 instances in 2 packages

Potential vulnerability

Supply chain risk

Initial human review suggests the presence of a vulnerability in this package. It is pending further analysis and confirmation.

Found 1 instance in 1 package

URL strings

Supply chain risk

Package contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.

Found 801 instances in 801 packages

Environment variable access

Supply chain risk

Package accesses environment variables, which may be a sign of credential stuffing or data theft.

Found 108 instances in 108 packages

Filesystem access

Supply chain risk

Accesses the file system, and could potentially read sensitive data.

Found 868 instances in 868 packages

Unidentified License

License

(Experimental) Something that seems like a license was found, but its contents could not be matched with a known license.

Found 569 instances in 282 packages

Unmaintained

Maintenance

Package has not been updated in more than 5 years and may be unmaintained. Problems with the package may go unaddressed.

Found 4 instances in 4 packages

Copyleft License

License

(Experimental) Copyleft license information was found.

Found 147 instances in 146 packages

Non-permissive License

License

(Experimental) A license not known to be considered permissive was found.

Found 263 instances in 262 packages

AI-detected potential code anomaly

Supply chain risk

AI has identified unusual behaviors that may pose a security risk.

Found 4 instances in 4 packages

Ambiguous License Classifier

License

(Experimental) An ambiguous license classifier was found.

Found 3 instances in 2 packages

License exception

License

(Experimental) Contains an SPDX license exception.

Found 53 instances in 52 packages

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

About

  • About
  • Love
  • Blog
  • Glossary
  • CareersHiring
  • Send Feedback
  • Contact Us
  • System Status

Packages

Explore npm
Explore Go
Explore Maven
Explore NuGet
Explore PyPI
Explore Rubygems

Stay in touch

Get open source security insights delivered straight into your inbox.

  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc

U.S. Patent No. 12,346,443 & 12,314,394. Other pending.

Shell access

Instance

Instance #1

Alert Locations
Loading...