PyPI · pypi.org
magic-pocket
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 0.2.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · magic_pocket-0.2.1/packages/magic-pocket-cli/pocket_cli/resources/cloudfront.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · magic_pocket-0.2.1/packages/magic-pocket-cli/pocket_cli/resources/aws/builders/depot.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.2.1 | High risk | 55 | 2026-06-10 |
0.2.0 | High risk | 55 | 2026-06-10 |
Block this in CI
pkgradar gate --ecosystem pypi magic-pocket==0.2.1