PyPI · pypi.org
graqle
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 0.75.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · graqle-0.75.1/graqle/ontology/domain_detector.py |
| medium | Remote Payload | matched "curl " · graqle-0.75.1/action/pr-guardian/entrypoint.sh |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · graqle-0.75.1/graqle/runtime/detector.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · graqle-0.75.1/graqle/scanner/autodetect.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.75.1 | High risk | 117 | 2026-06-15 |
0.75.0 | High risk | 117 | 2026-06-09 |
0.74.0 | Review | 77 | 2026-06-08 |
0.73.0 | Review | 77 | 2026-06-08 |
0.72.2 | Review | 77 | 2026-06-08 |
0.72.1 | Review | 77 | 2026-06-08 |
0.72.0 | Review | 77 | 2026-06-07 |
0.71.0 | Review | 77 | 2026-06-07 |
0.70.1 | Review | 77 | 2026-06-06 |
0.70.0 | Review | 77 | 2026-06-05 |
0.69.0 | Review | 77 | 2026-06-04 |
0.68.1 | Review | 77 | 2026-06-03 |
0.68.0 | Review | 77 | 2026-06-01 |
0.67.0 | Review | 77 | 2026-06-01 |
0.66.0 | Review | 77 | 2026-06-01 |
0.65.0 | Review | 77 | 2026-05-31 |
0.64.0 | Review | 77 | 2026-05-31 |
0.63.1 | Review | 77 | 2026-05-31 |
0.63.0 | Review | 77 | 2026-05-31 |
0.62.3 | Review | 77 | 2026-05-30 |
0.62.2 | Review | 77 | 2026-05-30 |
0.62.1 | Review | 77 | 2026-05-30 |
0.62.0 | Review | 77 | 2026-05-30 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi graqle==0.75.1