Two corrections to my own review of TrustSight, since both went to the list.
First, the neovim-git instability is real but I described it wrongly. For commit 99d9d479, inspect scores 0/100 with no findings when the local dependency corpus is unseeded, because the D-series is deliberately silent on an empty table, and 25/100 with D001, "Novel Dependency Added: optdepends 'tree-sitter-cli' has never been seen in the AUR", when the corpus is populated but lacks that name. The run folds the names it just saw into its own corpus, so an immediate rerun of the identical command falls back to 0/100. So the same command has three possible answers, but the sequence is 0 and 25, not the 0/15/0 I wrote. "Maintainer first seen for this package" is not a rule: it is a tier-C novelty score component, and it never appears in --last output at all, because the second RPC lookup gets a trimmed record back with no maintainer field. Second, on qt5-styleplugins f15a54a1: it adds one new patch file and renames the existing one; git reports the rename as R100 with byte-identical content. The new entry is the third element of source and sha512sums, not the second. With rename detection off git shows two additions and one deletion, which is where my "two patch files" came from. The finding itself stands: that commit still comes back as "No findings", 0/100. I have sent Emiliano the full reproduction material with commands and verbatim output for all three cases. Alexander Berg
