PkgRadar

PyPI · pypi.org

harness-maker

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.29.1

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · harness_maker-0.29.1/src/harness_maker/profile.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.29.1High risk652026-06-11
0.29.0Review252026-06-07
0.28.11Review202026-06-03
0.28.9Review202026-06-02
0.28.8Review202026-06-02
0.28.6Review202026-06-02
0.28.5Review202026-06-02
0.28.4Review202026-05-31
0.28.2Review202026-05-31
0.28.1Review202026-05-31
0.28.0Review202026-05-30
0.27.1Review202026-05-28
0.26.8Review202026-05-28
0.26.7Review202026-05-28
0.26.6Review202026-05-28
0.26.5Review202026-05-28

Block this in CI

PkgRadar gates harness-maker (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi harness-maker==0.29.1