PkgRadar

PyPI · pypi.org

locus-sdk

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.2.0b27

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · locus_sdk-0.2.0b27/src/locus/integrations/fastmcp.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · locus_sdk-0.2.0b27/src/locus/integrations/osv.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.0b27High risk502026-06-10
0.2.0b26Low risk02026-05-30
0.2.0b25Low risk02026-05-30
0.2.0b24Low risk02026-05-29
0.2.0b23Low risk02026-05-28

Block this in CI

PkgRadar gates locus-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi locus-sdk==0.2.0b27