PyPI · pypi.org
hyperweave
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 0.4.0a3
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · hyperweave-0.4.0a3/scripts/extract_glyphs.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · hyperweave-0.4.0a3/src/hyperweave/render/glyphs.py |
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('os') — reflection bypass for static checks. · hyperweave-0.4.0a3/scripts/stress_test.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.4.0a3 | High risk | 80 | 2026-06-16 |
0.4.0a2 | High risk | 80 | 2026-06-11 |
0.4.0a1 | High risk | 30 | 2026-06-09 |
0.3.14 | High risk | 30 | 2026-06-04 |
0.3.13 | High risk | 30 | 2026-06-04 |
0.3.12 | High risk | 30 | 2026-06-02 |
0.3.11 | High risk | 30 | 2026-05-30 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi hyperweave==0.4.0a3