Loading the latest scan…
PyPI · pypi.org
Credential file access, Python Bun Js Exec, Py Runtime Base64 Decode +4 more
Why PkgRadar flagged 0.19.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | — |
| medium | Python Bun Js Exec | — |
| medium | Python Bun Js Exec | — |
| medium | Python Bun Js Exec | — |
| medium | Python Bun Js Exec | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Dynamic Dangerous Import | — |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.19.0 | High risk | 260 | 2026-07-20 |
0.18.2 | High risk | 245 | 2026-07-08 |
0.18.1 | High risk | 245 | 2026-07-08 |
0.16.0 | High risk | 227 | 2026-07-03 |
0.15.1 | High risk | 211 | 2026-07-03 |
0.17.0 | High risk | 283 | 2026-07-03 |
0.18.0 | High risk | 273 | 2026-07-03 |
0.15.2 | High risk | 214 | 2026-07-03 |
0.15.0 | High risk | 211 | 2026-07-03 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi hermes-agent==0.19.0