PkgRadar

PyPI · pypi.org

ocaya

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 3.1.8

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · ocaya-3.1.8/ocaya/core/tools/arity.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.1.8High risk402026-06-11
3.1.7High risk402026-06-10
3.1.6High risk402026-06-09
3.1.5High risk402026-06-09
3.1.4High risk402026-06-09
3.1.3High risk402026-06-09
3.1.2High risk402026-06-09
3.1.1Low risk02026-06-08
3.1.0Low risk02026-06-08
3.0.0Low risk02026-06-08
2.15.14Low risk02026-06-08
2.15.13Low risk02026-06-07
2.15.12Low risk02026-06-07
2.15.11Low risk02026-06-07
2.15.10Low risk02026-06-07
2.15.9Low risk02026-06-07
2.15.8Low risk02026-06-07
2.15.7Low risk02026-06-07
2.15.6Low risk02026-06-07
2.15.5Low risk02026-06-07
2.15.4Low risk02026-06-06
2.15.3Low risk02026-06-06
2.15.2Low risk02026-06-06
2.15.1Low risk02026-06-06
2.15.0Low risk02026-06-06
2.14.0Low risk02026-06-06

Block this in CI

PkgRadar gates ocaya (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ocaya==3.1.8