PkgRadar

PyPI · pypi.org

claw-forge

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.8.70

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · claw_forge-0.8.70/claw_forge/config.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · claw_forge-0.8.70/claw_forge/git/shared_resolve.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.70High risk552026-06-15
0.8.69High risk552026-06-13
0.8.68High risk552026-06-12
0.8.67High risk552026-06-10
0.8.66Review52026-06-10
0.8.65Review52026-06-10
0.8.64Review52026-06-09
0.8.63Review52026-06-09
0.8.62Review52026-06-09
0.8.61Review52026-06-08
0.8.60Review52026-06-08
0.8.59Review52026-06-08
0.8.57Review52026-06-05
0.8.56Review52026-06-05
0.8.55Review52026-06-05
0.8.54Review52026-06-05
0.8.53Review52026-06-04
0.8.52Review52026-06-04
0.8.51Review52026-06-03
0.8.50Review52026-06-03
0.8.49Review52026-05-31
0.8.48Review102026-05-29
0.8.47Review102026-05-29
0.8.46Review102026-05-29

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates claw-forge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi claw-forge==0.8.70