PkgRadar

PyPI · pypi.org

graqle

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.75.1

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · graqle-0.75.1/graqle/ontology/domain_detector.py
mediumRemote Payloadmatched "curl " · graqle-0.75.1/action/pr-guardian/entrypoint.sh
mediumCredential file accessmatched "AWS_ACCESS_KEY" · graqle-0.75.1/graqle/runtime/detector.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · graqle-0.75.1/graqle/scanner/autodetect.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.75.1High risk1172026-06-15
0.75.0High risk1172026-06-09
0.74.0Review772026-06-08
0.73.0Review772026-06-08
0.72.2Review772026-06-08
0.72.1Review772026-06-08
0.72.0Review772026-06-07
0.71.0Review772026-06-07
0.70.1Review772026-06-06
0.70.0Review772026-06-05
0.69.0Review772026-06-04
0.68.1Review772026-06-03
0.68.0Review772026-06-01
0.67.0Review772026-06-01
0.66.0Review772026-06-01
0.65.0Review772026-05-31
0.64.0Review772026-05-31
0.63.1Review772026-05-31
0.63.0Review772026-05-31
0.62.3Review772026-05-30
0.62.2Review772026-05-30
0.62.1Review772026-05-30
0.62.0Review772026-05-30

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates graqle (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi graqle==0.75.1