PkgRadar

PyPI · pypi.org

deepline

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 1.0.101

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · deepline-1.0.101/deepline_core/http.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · deepline-1.0.101/deepline_core/self_update.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.101High risk502026-06-16
1.0.100High risk502026-06-16
1.0.99High risk402026-06-16
1.0.98High risk402026-06-16
1.0.97High risk402026-06-15
1.0.96High risk402026-06-15
1.0.95High risk402026-06-15
1.0.94High risk402026-06-15
1.0.93High risk402026-06-12
1.0.92High risk402026-06-12
1.0.91High risk402026-06-11
1.0.90High risk402026-06-09
1.0.89Low risk02026-06-09
1.0.88Low risk02026-06-05
1.0.87Low risk02026-06-04
1.0.86Low risk02026-06-03
1.0.85Low risk02026-06-02
1.0.84Low risk02026-06-02
1.0.83Low risk02026-06-02
1.0.82Low risk02026-06-02
1.0.81Low risk02026-06-02
1.0.80Low risk02026-06-01
1.0.73Low risk02026-05-30
1.0.72Low risk02026-05-30
1.0.79Low risk02026-05-29
1.0.78Low risk02026-05-29
1.0.77Low risk02026-05-28
1.0.76Review122026-05-27
1.0.75Review122026-05-27
1.0.74Review122026-05-27

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates deepline (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi deepline==1.0.101