PkgRadar

PyPI · pypi.org

hugo

Py Custom Build Backend: Non-standard PEP 517 build-backend `hugo_meson_python_wrapper` — runs custom code at install time.

Why PkgRadar flagged 0.163.1

SeveritySignalEvidence
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `hugo_meson_python_wrapper` — runs custom code at install time. · pyproject.toml
mediumRemote Payloadmatched "raw.githubusercontent.com" · hugo-0.163.1/hugo-src/livereload/gen/main.go

Scanned versions

VersionVerdictScoreScanned (UTC)
0.163.1Review152026-06-11
0.163.0Review152026-06-08
0.162.1Review152026-06-01
0.162.0.1Low risk02026-05-28
0.162.0Review252026-05-27

Block this in CI

PkgRadar gates hugo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi hugo==0.163.1