PkgRadar

PyPI · pypi.org

cache-dit

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 1.5.0

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · cache_dit/_utils/examples.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.0High risk202026-06-16
1.3.12Low risk02026-06-09
1.3.11Low risk02026-06-04
1.3.10Low risk02026-06-04
1.3.9Review82026-05-27

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates cache-dit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi cache-dit==1.5.0