Package evidence
@optave/[email protected]
Remote Dependency Spec: devDependencies.tree-sitter-clojure="github:sogaiu/tree-sitter-clojure"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 50
- First published
- Feb 2026
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@optave/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@optave/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: devDependencies.tree-sitter-clojure="github:sogaiu/tree-sitter-clojure"
1 remote tarball(s) were followed statically.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (2 events)
- available → available · risk review · score 40 · status available -> available, risk high -> review, score 67 -> 40
- new → available · risk high · score 67 · status changed
Evidence
Static findings
4 static · 1 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Dependency Spec | package.json | devDependencies.tree-sitter-clojure="github:sogaiu/tree-sitter-clojure" | 8 |
| medium | Remote Dependency Spec | package.json | devDependencies.tree-sitter-erlang="github:WhatsApp/tree-sitter-erlang#semver:*" | 8 |
| medium | Remote Dependency Spec | package.json | devDependencies.tree-sitter-fsharp="https://github.com/ionide/tree-sitter-fsharp/archive/refs/tags/0.3.0.tar.gz" | 8 |
| medium | Remote Dependency Spec | package.json | devDependencies.tree-sitter-gleam="github:gleam-lang/tree-sitter-gleam" | 8 |
| medium | Dependency Changed To Remote Vs Previous | package.json | devDependencies.tree-sitter-fsharp changed to remote spec in 3.11.0 vs 3.10.0: "https://github.com/ionide/tree-sitter-fsharp/archive/refs/tags/0.3.0.tar.gz" | 8 |
Remote payloads
Followed remote artifacts
| Source | URL | Risk | Score | Summary |
|---|---|---|---|---|
| devDependencies.tree-sitter-fsharp | https://github.com/ionide/tree-sitter-fsharp/archive/refs/tags/0.3.0.tar.gz | error | 0 | unexpected end of file |
Manifest
Package metadata
Scripts19
benchmarknode --experimental-strip-types --import ./scripts/ts-resolve-loader.js scripts/benchmark.tsbuildtsc && node -e "require('fs').writeFileSync('dist/index.cjs',require('fs').readFileSync('src/index.cjs','utf8').replaceAll('./index.ts','./index.js'))"build:wasmnode scripts/node-ts.js scripts/build-wasm.tscleannode -e "require('fs').rmSync('dist',{recursive:true,force:true});require('fs').rmSync('.tsbuildinfo',{force:true})"deps:treenode scripts/node-ts.js scripts/gen-deps.tsformatbiome format --write src/ tests/lintbiome check src/ tests/lint:fixbiome check --write src/ tests/prepacknpm run buildpreparenpm run build:wasm && npm run build && husky && npm run deps:treereleasecommit-and-tag-versionrelease:dry-runcommit-and-tag-version --dry-runtestvitest runtest:coveragevitest run --coveragetest:regression-guardvitest run tests/benchmarks/regression-guard.test.tstest:watchvitesttypechecktsc --noEmitverify-importsnode scripts/node-ts.js scripts/verify-imports.tsversionnode scripts/node-ts.js scripts/sync-native-versions.ts && git add package.json crates/codegraph-core/Cargo.toml
Dependencies3
better-sqlite3^12.6.2commander^14.0.3web-tree-sitter^0.26.5
Optional dependencies7
@modelcontextprotocol/sdk^1.0.0@optave/codegraph-darwin-arm643.11.0@optave/codegraph-darwin-x643.11.0@optave/codegraph-linux-arm64-gnu3.11.0@optave/codegraph-linux-x64-gnu3.11.0@optave/codegraph-linux-x64-musl3.11.0@optave/codegraph-win32-x64-msvc3.11.0