PkgRadar

PyPI · pypi.org

marin-levanter

Py Custom Build Backend: Non-standard PEP 517 build-backend `uv_build` — runs custom code at install time.

Why PkgRadar flagged 0.2.15.dev202606130841

SeveritySignalEvidence
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml
mediumCredential file accessmatched "AWS_ACCESS_KEY" · marin_levanter-0.2.15.dev202606130841/src/levanter/tensorstore_serialization.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.15.dev202606130841Review302026-06-13
0.2.14.dev202606120949Review302026-06-12
0.2.13.dev202606110957Review302026-06-11
0.2.12.dev202606100934Review302026-06-10
0.2.11.dev202606081009Review302026-06-08
0.2.10.dev202606070840Review302026-06-07
0.2.9.dev202606060818Review302026-06-06
0.2.8.dev202606050858Review302026-06-05
0.2.7.dev202606040937Review302026-06-04
0.2.6.dev202606031026Review302026-06-03
0.2.5.dev202606020954Review302026-06-02
0.2.4.dev202606011101Review302026-06-01
0.2.3.dev202605310830Review302026-05-31
0.2.2.dev202605300811Review302026-05-30
0.2.1.dev202605292307Review302026-05-29

Block this in CI

PkgRadar gates marin-levanter (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi marin-levanter==0.2.15.dev202606130841