PkgRadar

PyPI · pypi.org

deepagents-code

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.1.19

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · deepagents_code-0.1.19/deepagents_code/local_context.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.19High risk452026-06-17
0.1.18High risk452026-06-16
0.1.17High risk452026-06-16
0.1.16High risk452026-06-13
0.1.15High risk452026-06-12
0.1.14High risk452026-06-12
0.1.12High risk452026-06-10
0.1.11Review52026-06-08
0.1.10Review52026-06-05
0.1.9Review52026-06-03
0.1.8Review52026-06-02
0.1.5Review52026-05-30
0.1.7Review52026-05-30
0.1.6Review272026-05-27

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates deepagents-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi deepagents-code==0.1.19