PkgRadar

PyPI · pypi.org

coworld

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.1.22

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · coworld-0.1.22/src/coworld/optimizer/runtime.py
mediumCredential file accessmatched ".aws/" · coworld-0.1.22/src/coworld/upload.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.22High risk552026-06-10
0.1.21High risk552026-06-10
0.1.20Review152026-06-08
0.1.19Review152026-06-08
0.1.18Review152026-06-08
0.1.17Review152026-06-08
0.1.16Review152026-06-05
0.1.15Review152026-06-04
0.1.14Review152026-06-03
0.1.13Review152026-05-31
0.1.12Review152026-05-29
0.0.0Review152026-05-29

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates coworld (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi coworld==0.1.22