PkgRadar

Pub (Dart) · pub.dev

tree_sitter_language_pack

Dart Ffi Process Combo: File mixes dart:ffi native loads with Process.run/start — escape-hatch chain.

Why PkgRadar flagged 1.9.0-rc.34

SeveritySignalEvidence
mediumDart Ffi Process ComboFile mixes dart:ffi native loads with Process.run/start — escape-hatch chain. · bin/download_libs.dart

Scanned versions

VersionVerdictScoreScanned (UTC)
1.9.0-rc.34Review152026-06-12
1.9.0-rc.33Low risk02026-06-11
1.9.0-rc.32Low risk02026-06-11
1.9.0-rc.28Low risk02026-06-08
1.9.0-rc.27Low risk02026-06-08
1.9.0-rc.26Low risk02026-06-08
1.9.0-rc.25Low risk02026-06-07
1.9.0-rc.24Low risk02026-06-07
1.9.0-rc.23Low risk02026-06-06
1.9.0-rc.22Low risk02026-06-06
1.9.0-rc.21Low risk02026-06-06
1.9.0-rc.20Low risk02026-06-05
1.9.0-rc.19Low risk02026-06-04
1.9.0-rc.18Low risk02026-06-04
1.9.0-rc.17Low risk02026-05-29
1.9.0-rc.16Low risk02026-05-29
1.9.0-rc.14Low risk02026-05-29
1.9.0-rc.15Low risk02026-05-29

Block this in CI

PkgRadar gates tree_sitter_language_pack (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pub [email protected]