PkgRadar

npm · registry.npmjs.org

@opencode-ai/cli

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 12 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 0.0.0-dev-202606051841

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 12 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.0-dev-202606051841Review42026-06-05
0.0.0-dev-202606051816Review42026-06-05
0.0.0-dev-202606051751Review42026-06-05
0.0.0-dev-202606051623Review42026-06-05
0.0.0-dev-202606051645Review42026-06-05
0.0.0-dev-202606051301Review42026-06-05
0.0.0-dev-202606051240Review42026-06-05
0.0.0-beta-202606051216Review42026-06-05
0.0.0-beta-202606051149Review42026-06-05
0.0.0-dev-202606051122Review42026-06-05
0.0.0-beta-202606051005Review42026-06-05
0.0.0-dev-202606051005Review42026-06-05
0.0.0-dev-202606050946Review42026-06-05
0.0.0-beta-202606050844Review42026-06-05
0.0.0-beta-202606050814Review42026-06-05
0.0.0-dev-202606050801Review42026-06-05
0.0.0-dev-202606050743Review42026-06-05
0.0.0-dev-202606050650Review42026-06-05
0.0.0-beta-202606050635Review42026-06-05
0.0.0-beta-202606050607Review42026-06-05
0.0.0-dev-202606050532Review42026-06-05
0.0.0-dev-202606050501Review42026-06-05
0.0.0-beta-202606050413Review42026-06-05
0.0.0-dev-202606050345Review42026-06-05
0.0.0-dev-202606050325Review42026-06-05
0.0.0-dev-202606050309Review42026-06-05
1.16.0Review42026-06-05
0.0.0-beta-202606050205Review42026-06-05
0.0.0-beta-202606050139Review42026-06-05
0.0.0-dev-202606050108Review42026-06-05
0.0.0-dev-202606050049Review42026-06-05
0.0.0-beta-202606050026Review42026-06-05
0.0.0-dev-202606050002Review42026-06-05
0.0.0-beta-202606050000Review42026-06-05
0.0.0-dev-202606042344Review42026-06-05
0.0.0-dev-202606042324Review42026-06-04
0.0.0-dev-202606042328Review152026-06-04
0.0.0Low risk02026-06-04

Block this in CI

PkgRadar gates @opencode-ai/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @opencode-ai/[email protected]