PkgRadar

PyPI · pypi.org

rovr

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.9.1.post1

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · rovr-0.9.1.post1/src/rovr/variables/maps.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.1.post1High risk422026-06-13
0.9.1Review142026-06-08
0.9.0Review142026-06-01

Block this in CI

PkgRadar gates rovr (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi rovr==0.9.1.post1