PkgRadar

PyPI · pypi.org

tensorlake

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 0.5.41

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · tensorlake-0.5.41/src/tensorlake/vendor/faker/decode/codes.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.41High risk282026-06-12
0.5.40High risk282026-06-12
0.5.38High risk282026-06-10
0.5.37High risk282026-06-10
0.5.36High risk282026-06-10
0.5.35High risk282026-06-09
0.5.34Low risk02026-06-08
0.5.33Low risk02026-06-07
0.5.32Low risk02026-06-04
0.5.31Low risk02026-06-03
0.5.30Low risk02026-06-03
0.5.29Low risk02026-06-02
0.5.28Low risk02026-06-02
0.5.27Low risk02026-05-30
0.5.26Low risk02026-05-30
0.5.25Low risk02026-05-29
0.5.24Low risk02026-05-29
0.5.23Low risk02026-05-28
0.5.22Low risk02026-05-28
0.5.21Review362026-05-28
0.5.20Review362026-05-27
0.5.19Review362026-05-26

Block this in CI

PkgRadar gates tensorlake (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi tensorlake==0.5.41