PkgRadar

PyPI · pypi.org

shap

Known Indicator Filename: shap-0.52.0/shap/plots/resources/bundle.js

Why PkgRadar flagged 0.52.0

SeveritySignalEvidence
highKnown Indicator Filenameshap-0.52.0/shap/plots/resources/bundle.js · shap-0.52.0/shap/plots/resources/bundle.js
mediumObfuscation Densityhigh encoded/escaped-token density · shap-0.52.0/javascript/package-lock.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.52.0Review172026-05-28

Block this in CI

PkgRadar gates shap (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi shap==0.52.0