PkgRadar

PyPI · pypi.org

hermes-dec

Py Custom Build Backend: Non-standard PEP 517 build-backend `uv_build` — runs custom code at install time.

Why PkgRadar flagged 0.1.4

SeveritySignalEvidence
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml
mediumRemote Payloadmatched "wget " · hermes_dec-0.1.4/src/hermes_dec/utils/original_function_builtins_c_src/get_source_codes.sh
mediumRemote Payloadmatched "wget " · hermes_dec-0.1.4/src/hermes_dec/utils/original_hermes_bytecode_c_src/get_source_codes.sh
mediumRemote Payloadmatched "wget " · hermes_dec-0.1.4/src/hermes_dec/utils/original_regex_bytecode_c_src/get_source_codes.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.4High risk512026-06-06

Block this in CI

PkgRadar gates hermes-dec (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi hermes-dec==0.1.4