PkgRadar

PyPI · pypi.org

remaind

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.9.25

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · remaind-0.9.25/src/remaind/commands/daemon.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.25High risk432026-06-16
0.9.24High risk432026-06-14
0.9.15High risk432026-06-11
0.9.14High risk432026-06-11
0.9.13High risk432026-06-11
0.9.12High risk432026-06-11
0.9.11High risk432026-06-11
0.9.10High risk432026-06-11
0.9.9High risk432026-06-11
0.9.8Review32026-06-03
0.9.7Review32026-06-02

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates remaind (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi remaind==0.9.25