PkgRadar

npm · registry.npmjs.org

@plannotator/opencode

Install Lifecycle Suppresses Failure: postinstall="mkdir -p ${XDG_CONFIG_HOME:-$HOME/.config}/opencode/commands && cp ./commands/*.md ${XDG_CONFIG_HOME:-$HOME/.config}/opencode/commands/ 2>/dev/null || true"

Why PkgRadar flagged 0.20.3

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="mkdir -p ${XDG_CONFIG_HOME:-$HOME/.config}/opencode/commands && cp ./commands/*.md ${XDG_CONFIG_HOME:-$HOME/.config}/opencode/commands/ 2>/dev/null || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.20.3Review72026-06-16
0.20.2Review72026-06-14
0.20.1Review72026-06-10
0.20.0Review72026-06-09
0.19.27Review72026-06-03
0.19.26Review72026-06-01
0.19.25Review72026-06-01
0.19.24Review102026-05-28
0.19.23Review102026-05-25
0.19.21Review352026-05-24
0.19.22Review352026-05-24

Block this in CI

PkgRadar gates @plannotator/opencode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @plannotator/[email protected]