PkgRadar

PyPI · pypi.org

aacode

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 1.7.16

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · aacode-1.7.16/aacode/utils/safety.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.7.16High risk402026-06-14
1.7.15High risk402026-06-13
1.7.14High risk402026-06-11
1.7.13High risk402026-06-09
1.7.12Low risk02026-06-08
1.7.11Low risk02026-06-07
1.7.10Low risk02026-06-06
1.7.9Low risk02026-06-02
1.7.8Low risk02026-05-31
1.7.7Low risk02026-05-30
1.7.5Review292026-05-27

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates aacode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aacode==1.7.16