PkgRadar

PyPI · pypi.org

pulse-framework

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.1.102

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · pulse_framework-0.1.102/src/pulse/cli/cmd.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · pulse_framework-0.1.102/src/pulse/cli/dependencies.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · pulse_framework-0.1.102/src/pulse/cli/packages.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.102High risk452026-06-16
0.1.101High risk452026-06-09
0.1.100High risk452026-06-09
0.1.99Review102026-06-06
0.1.98Review102026-06-06
0.1.97Review102026-06-03
0.1.96Review102026-06-01
0.1.95Review102026-05-29
0.1.94Review102026-05-29
0.1.93Review102026-05-29
0.1.92Review102026-05-28
0.1.91Review102026-05-28
0.1.90Review102026-05-28
0.1.89Review102026-05-28
0.1.88Review102026-05-26

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates pulse-framework (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pulse-framework==0.1.102