PkgRadar

PyPI · pypi.org

fluid-labels

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 9.9.0

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · fluid_labels-9.9.0/labels/core/merge_packages.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · fluid_labels-9.9.0/labels/model/package_manager.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · fluid_labels-9.9.0/labels/parsers/cataloger/javascript/cataloger.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · fluid_labels-9.9.0/labels/parsers/cataloger/javascript/parse_bun_lock.py

Scanned versions

VersionVerdictScoreScanned (UTC)
9.9.0High risk272026-06-12
9.8.0High risk272026-06-11
9.7.0Review22026-06-04
9.6.0Review22026-06-04
9.5.0Review22026-05-29
9.4.0Review152026-05-27
9.3.1Review152026-05-27
9.3.0Review152026-05-27
9.2.0Review152026-05-26
9.1.0Review302026-05-26

Block this in CI

PkgRadar gates fluid-labels (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi fluid-labels==9.9.0