PkgRadar

PyPI · pypi.org

nerftools

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 4.1.0

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · nerftools-4.1.0/nerftools/builder.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.1.0High risk492026-06-15
4.0.0High risk492026-06-10
3.0.0Review92026-06-07
2.2.0Review92026-06-05
2.1.0Review92026-06-03

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates nerftools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi nerftools==4.1.0