PkgRadar

PyPI · pypi.org

apollotab

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.2.4

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · apollotab-0.2.4/venv/Lib/site-packages/pygments/lexers/_vim_builtins.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · apollotab-0.2.4/venv/Lib/site-packages/docutils/writers/odf_odt/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · apollotab-0.2.4/venv/Lib/site-packages/jaraco/context/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · apollotab-0.2.4/venv/Lib/site-packages/PyQt5/uic/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · apollotab-0.2.4/venv/Lib/site-packages/jaraco/functools/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · apollotab-0.2.4/venv/Lib/site-packages/pip/_vendor/pkg_resources/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · apollotab-0.2.4/venv/Lib/site-packages/jaraco/context/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.4High risk1942026-06-12
0.2.3High risk1942026-06-12
0.2.2High risk1942026-06-12
0.2.1Low risk02026-06-12
0.2.0Low risk02026-06-12

Block this in CI

PkgRadar gates apollotab (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi apollotab==0.2.4