← Home

@optave/codegraph

Local code graph CLI — parse codebases with tree-sitter, build dependency graphs, query them

39
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

optave-admin

Keywords

codegraphdependency-graphcode-analysistree-sitterstatic-analysiscall-graphimpact-analysismcp

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata url-dep:tree-sitter-gleam AI (npm-metadata): devDependency grammar repo, not shipped; standard tree-sitter ecosystem pattern. ai
npm-metadata url-dep:tree-sitter-erlang AI (npm-metadata): devDependency grammar repo, not shipped; standard tree-sitter ecosystem pattern. ai
npm-metadata url-dep:tree-sitter-fsharp AI (npm-metadata): devDependency grammar repo, not shipped; standard tree-sitter ecosystem pattern. ai
npm-metadata url-dep:tree-sitter-clojure AI (npm-metadata): devDependency grammar repo, not shipped; standard tree-sitter ecosystem pattern. ai
npm-metadata bundled-binaries AI (npm-metadata): Tree-sitter wasm grammars are the package's core parsing engines, not backdoors. ai
semgrep semgrep:dynamic-require AI (semgrep): Native binding loader pattern for optional native module, standard for this package type. ai

Versions (showing 39 of 39)

Version Deps Published
3.16.0 3 / 43
3.15.0 3 / 43
3.13.0 3 / 43
3.12.0 3 / 44
3.11.2 3 / 44
3.11.1 3 / 44
3.10.0 3 / 44
3.9.6 3 / 44
3.7.0 3 / 33
3.6.0 3 / 27
3.5.0 3 / 21
3.4.1 3 / 21
3.4.0 3 / 20
3.3.1 5 / 20
3.3.0 5 / 20
3.2.0 5 / 19
3.1.5 5 / 19
3.1.4 5 / 19
3.1.3 5 / 19
3.1.2 5 / 19
3.1.1 5 / 19
3.1.0 5 / 19
3.0.4 5 / 19
3.0.3 5 / 19
3.0.2 5 / 19
3.0.1 5 / 19
3.0.0 5 / 19
2.6.0 5 / 19
2.5.1 5 / 18
2.5.0 5 / 18
2.4.0 3 / 18
2.3.0 3 / 18
2.2.1 3 / 18
2.2.0 3 / 18
2.1.0 3 / 18
2.0.0 3 / 18
1.4.1 3 / 18
1.3.0 3 / 18
1.1.0 3 / 7

v3.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.0

3 findings
HIGH Bundled binary files (23) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-bash.wasm • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-c.wasm • grammars/tree-sitter-cpp.wasm • grammars/tree-sitter-dart.wasm • grammars/tree-sitter-elixir.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-haskell.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm ... and 13 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-04-01, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-04-01, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.6.0

3 findings
HIGH Bundled binary files (17) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-bash.wasm • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-c.wasm • grammars/tree-sitter-cpp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-kotlin.wasm • grammars/tree-sitter-php.wasm ... and 7 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.5.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.4.1

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.4.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.3.1

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.3.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.2.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-17, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.5

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-17, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.4

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.3

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.2

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.1

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-09, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-08, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.4

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-06, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.3

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.2

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.1

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.6.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-03-02, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-03-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.5.1

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-28, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.5.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-28, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.4.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-24, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.2.1

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.2.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.1.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.0.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.4.1

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.3.0

3 findings
HIGH Bundled binary files (11) npm-metadata

Package contains compiled binaries that could be backdoors: • grammars/tree-sitter-c_sharp.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-hcl.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-php.wasm • grammars/tree-sitter-python.wasm • grammars/tree-sitter-ruby.wasm • grammars/tree-sitter-rust.wasm • grammars/tree-sitter-tsx.wasm ... and 1 more

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: optave-admin → GitHub Actions (on 2026-02-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (optave-admin) on 2026-02-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.