PyPI · pypi.org
evo-hq-cli
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 0.6.0a1
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · evo_hq_cli-0.6.0a1/src/evo/host_install/openclaw.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · evo_hq_cli-0.6.0a1/src/evo/host_install/opencode.py |
| medium | Py Import Time Subprocess | subprocess call — process spawning. · evo_hq_cli-0.6.0a1/src/evo/host_install/__init__.py |
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('sys') — reflection bypass for static checks. · evo_hq_cli-0.6.0a1/src/evo/host_install/codex.py |
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('sys') — reflection bypass for static checks. · evo_hq_cli-0.6.0a1/src/evo/host_install/openclaw.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · evo_hq_cli-0.6.0a1/src/evo/dashboard.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.6.0a1 | High risk | 147 | 2026-06-17 |
0.5.3 | High risk | 147 | 2026-06-14 |
0.5.2 | High risk | 147 | 2026-06-11 |
0.5.1 | High risk | 147 | 2026-06-11 |
0.5.0 | High risk | 97 | 2026-06-06 |
0.5.0a13 | High risk | 97 | 2026-06-05 |
0.5.0a12 | High risk | 97 | 2026-06-05 |
0.5.0a11 | High risk | 97 | 2026-06-04 |
0.5.0a10 | High risk | 97 | 2026-06-04 |
0.5.0a9 | High risk | 97 | 2026-06-04 |
0.5.0a8 | High risk | 97 | 2026-06-04 |
0.4.5 | High risk | 97 | 2026-06-04 |
0.5.0a7 | High risk | 97 | 2026-06-02 |
0.5.0a6 | High risk | 97 | 2026-06-02 |
0.5.0a5 | High risk | 97 | 2026-06-01 |
0.5.0a4 | High risk | 97 | 2026-06-01 |
0.5.0a3 | High risk | 97 | 2026-06-01 |
0.4.4 | High risk | 97 | 2026-05-30 |
0.4.4a6 | High risk | 97 | 2026-05-30 |
0.4.4a5 | High risk | 97 | 2026-05-30 |
0.4.4a4 | High risk | 97 | 2026-05-30 |
0.4.4a3 | High risk | 97 | 2026-05-30 |
0.4.4a2 | High risk | 97 | 2026-05-30 |
0.4.4a1 | High risk | 97 | 2026-05-30 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi evo-hq-cli==0.6.0a1