PkgRadar

npm · registry.npmjs.org

@optave/codegraph

Remote Dependency Spec: devDependencies.tree-sitter-clojure="github:sogaiu/tree-sitter-clojure"

Why PkgRadar flagged 3.11.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.tree-sitter-clojure="github:sogaiu/tree-sitter-clojure" · package.json
mediumRemote Dependency SpecdevDependencies.tree-sitter-erlang="github:WhatsApp/tree-sitter-erlang#semver:*" · package.json
mediumRemote Dependency SpecdevDependencies.tree-sitter-fsharp="https://github.com/ionide/tree-sitter-fsharp/archive/refs/tags/0.3.0.tar.gz" · package.json
mediumRemote Dependency SpecdevDependencies.tree-sitter-gleam="github:gleam-lang/tree-sitter-gleam" · package.json
mediumDependency Changed To Remote Vs PreviousdevDependencies.tree-sitter-fsharp changed to remote spec in 3.11.0 vs 3.10.0: "https://github.com/ionide/tree-sitter-fsharp/archive/refs/tags/0.3.0.tar.gz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.11.0Review402026-06-03
3.11.2Review92026-06-01
3.11.1Review92026-05-30
3.10.0Review72026-05-25

Block this in CI

PkgRadar gates @optave/codegraph (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @optave/[email protected]