PkgRadar

PyPI · pypi.org

canvas

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.169.0

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · canvas-0.169.0/canvas_sdk/value_set/v2026/laboratory_test.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.169.0High risk272026-06-16
0.168.0High risk272026-06-16
0.167.1High risk272026-06-16
0.167.0High risk272026-06-13
0.166.0High risk272026-06-12
0.165.0High risk272026-06-09
0.164.0Review72026-06-08
0.163.1Review72026-06-04
0.163.0Review72026-06-03
0.162.0Review72026-06-03
0.161.0Review72026-06-02
0.160.0Review72026-06-02
0.159.0Review72026-06-02
0.158.1Review72026-06-01
0.158.0Review72026-06-01
0.157.0Review72026-05-29
0.156.0Review212026-05-27

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates canvas (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi canvas==0.169.0