PkgRadar

PyPI · pypi.org

marimo-base

Py Import Time Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 0.23.9

SeveritySignalEvidence
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · marimo_base-0.23.9/marimo/_runtime/_wasm/_duckdb/__init__.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml
mediumCredential file accessmatched "aws_access_key" · marimo_base-0.23.9/marimo/_server/ai/providers.py
mediumCredential file accessmatched "aws_access_key" · marimo_base-0.23.9/marimo/_smoke_tests/sql/redshift_example.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.23.9Review372026-06-04

Block this in CI

PkgRadar gates marimo-base (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi marimo-base==0.23.9