PkgRadar

PyPI · pypi.org

boutpp-nightly

Py Custom Build Backend: Non-standard PEP 517 build-backend `backend` — runs custom code at install time.

Why PkgRadar flagged 5.2.1.dev1067

SeveritySignalEvidence
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `backend` — runs custom code at install time. · pyproject.toml
mediumRemote Payloadmatched "github.com/LLNL/sundials/releases/download" · boutpp_nightly-5.2.1.dev1067/.build_sundials_for_ci.sh
mediumRemote Payloadmatched "curl " · boutpp_nightly-5.2.1.dev1067/.ci_script.sh
mediumRemote Payloadmatched "wget " · boutpp_nightly-5.2.1.dev1067/.codacy_coverage.sh
mediumRemote Payloadmatched "wget " · boutpp_nightly-5.2.1.dev1067/bin/bout-build-deps.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
5.2.1.dev1067High risk312026-06-11
5.2.1.dev1062High risk312026-06-11
5.2.1.dev1059High risk312026-06-04
5.2.1.dev961High risk312026-06-02
5.2.1.dev766High risk312026-06-01
5.2.1.dev758High risk312026-05-30
5.2.1.dev764Review312026-05-29
5.2.1.dev762Review312026-05-29
5.2.1.dev760Review312026-05-28

Block this in CI

PkgRadar gates boutpp-nightly (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi boutpp-nightly==5.2.1.dev1067