PyPI · pypi.org
marimo-base
Py Import Time Eval Exec: Python eval()/exec() called on a string.
Why PkgRadar flagged 0.23.9
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Import Time Eval Exec | Python eval()/exec() called on a string. · marimo_base-0.23.9/marimo/_runtime/_wasm/_duckdb/__init__.py |
| medium | Py Custom Build Backend | Non-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml |
| medium | Credential file access | matched "aws_access_key" · marimo_base-0.23.9/marimo/_server/ai/providers.py |
| medium | Credential file access | matched "aws_access_key" · marimo_base-0.23.9/marimo/_smoke_tests/sql/redshift_example.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.23.9 | Review | 37 | 2026-06-04 |
Block this in CI
pkgradar gate --ecosystem pypi marimo-base==0.23.9