PkgRadar

Package evidence

marin-levanter==0.2.15.dev202606130841

Py Custom Build Backend: Non-standard PEP 517 build-backend `uv_build` — runs custom code at install time.

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
14
First published
May 2026
Publisher
David Hall, Jason Wang, Ahmed Ahmed, Ivan Zhou, Will Held, Virginia Adams

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["marin-levanter==0.2.15.dev202606130841"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["marin-levanter==0.2.15.dev202606130841"],"fail_on":"review"}'
Artifact bytes616,657
Previous versionnone
Published2026-06-13T08:42:18
SHA-2562ca893d8c4583394781ee4c8025b501609ca7884fac9a8e93f6a5614feb54ead

Why flagged

What the scanner saw

Py Custom Build Backend: Non-standard PEP 517 build-backend `uv_build` — runs custom code at install time.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
30Score
0.2.15.dev202606130841Version
Status history (1 event)
  1. newavailable · risk review · score 30 · status changed

Evidence

Static findings

3 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumPy Custom Build Backendpyproject.tomlNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time.15
mediumCredential file accessmarin_levanter-0.2.15.dev202606130841/src/levanter/tensorstore_serialization.pymatched "AWS_ACCESS_KEY"10
Show all 3 findings (low-signal and informational)
SeverityKindPathDetailPoints
mediumPy Custom Build Backendpyproject.tomlNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time.15
mediumCredential file accessmarin_levanter-0.2.15.dev202606130841/src/levanter/tensorstore_serialization.pymatched "AWS_ACCESS_KEY"10
lowCredential file accessmarin_levanter-0.2.15.dev202606130841/src/levanter/infra/tpus.pymatched ".ssh/"5