PkgRadar

PyPI · pypi.org

slopmop

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 2.5.0

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · slopmop-2.5.0/slopmop/checks/javascript/lint_format.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · slopmop-2.5.0/slopmop/utils/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.0High risk772026-06-13
2.4.0High risk772026-06-12
2.3.2High risk772026-06-10
2.3.1High risk772026-06-09
2.3.0Review372026-06-08
2.2.0Review372026-06-07
2.1.0Review372026-06-03
2.0.2Review372026-06-03
2.0.1Review372026-06-02
2.0.0Review372026-05-31
1.6.0Review372026-05-30
1.5.0Review372026-05-28

Block this in CI

PkgRadar gates slopmop (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi slopmop==2.5.0