PkgRadar

PyPI · pypi.org

ciris-agent

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 2.9.6

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · ciris_adapters/bird/service.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · ciris_adapters/mcporter/service.py
highCredential file accessmatched "aws_access_key" · ciris_engine/schemas/api/config_security.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.9.6High risk952026-06-13
2.9.5High risk452026-06-07
2.9.4High risk452026-05-31
2.9.3High risk452026-05-30
2.9.2High risk452026-05-30

Block this in CI

PkgRadar gates ciris-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ciris-agent==2.9.6