wooldridge
A textbook data package whose whole job is to stay installable, and whose releases prove how much work that is.
A side-by-side editorial comparison of ClamAV and EDAForge — release velocity, themes, recent moves, and the top alternatives to consider.
Eight CVEs in one August batch — ClamAV's parser surface is the whole story.
ClamAV runs two supported lines, 1.5.x and 1.4.x, and publishes near-identical patch releases seconds apart whenever vulnerabilities land. The August pair is the largest yet in this window: eight CVEs in 1.5.4, six of them backported to 1.4.6, spanning the ZIP catalogue, GPT partition, PESpin, PDF, Mach-O and XAR parsers. Several reach back a decade or more — the PESpin overflow affects builds from 0.90 onward.
EDAForge is a data-quality auditor renamed mid-flight, still finding its CRAN footing.
EDAForge's release feed shows a package changing identity between its first two tags. The v0.1.0 notes describe DataAudit, a data-quality auditing package built around audit_data(), reusable audit_rules() and audit_score(), with install instructions still pointing at vinodhpmd/DataAudit, while the repository now serves EDAForge. Only three tags exist, one of which is a bare compare link with no notes, and the most recent is a CRAN-policy cleanup rather than feature work.
ClamAV runs two supported lines, 1.5.x and 1.4.x, and publishes near-identical patch releases seconds apart whenever vulnerabilities land. The August pair is the largest yet in this window: eight CVEs in 1.5.4, six of them backported to 1.4.6, spanning the ZIP catalogue, GPT partition, PESpin, PDF, Mach-O and XAR parsers. Several reach back a decade or more — the PESpin overflow affects builds from 0.90 onward.
Feature work has been paused since 1.5.0 last October; everything since is patch traffic against the file format parsers, and the batches are growing rather than shrinking. The August release widens the surface beyond parsing for the first time here, with a clamd STATS thread-safety bug that could disclose process memory or crash the daemon. Reporter credits increasingly come from automated discovery — Atuin, GitHub Security Lab, Trail of Bits — which suggests the find rate tracks the tooling pointed at this codebase, not new code being written.
Expect the dual-branch pattern to continue and per-batch CVE counts to stay high while automated fuzzing keeps sweeping the parser surface. These entries give no indication of a 1.6 line opening — there has been no development release since the 1.5.0 cycle.
EDAForge's release feed shows a package changing identity between its first two tags. The v0.1.0 notes describe DataAudit, a data-quality auditing package built around audit_data(), reusable audit_rules() and audit_score(), with install instructions still pointing at vinodhpmd/DataAudit, while the repository now serves EDAForge. Only three tags exist, one of which is a bare compare link with no notes, and the most recent is a CRAN-policy cleanup rather than feature work.
The substance so far is all in the DataAudit-named 0.1.0: more than a dozen check families spanning missing values, duplicates, ranges, patterns, dependencies and grouped sequences, wrapped in a structured report object with print and summary methods. The 0.1.1 that follows removes a default output path, moves examples to tempdir() and adds an introductory vignette, which is the standard shape of a package being made acceptable to CRAN. The public identity is currently ahead of the release notes, so a reader arriving at the feed cannot tell from it what EDAForge does.
Expect the next tag to align the notes with the EDAForge name and add exploratory-analysis functions alongside the auditing core; the compliance pass in 0.1.1 points at a CRAN submission as the near-term goal.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either ClamAV or EDAForge.
A textbook data package whose whole job is to stay installable, and whose releases prove how much work that is.
A graph-centrality package that spent 2026 making its existing measures usable at scale, then went quiet.
A test-theory package that grew into a graphical-model toolkit, now spending its releases paying down the API debt that growth created.
nuggets keeps compounding on the 2.0 rewrite — more pattern families, lighter install.
projoint spent a year on CRAN paperwork, then shipped a correctness fix it flagged itself.
eratosthenes spends 0.1.0 hardening inputs rather than adding chronology methods.
See all ClamAV alternatives → · See all EDAForge alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. ClamAV and EDAForge are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. ClamAV and EDAForge are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top ClamAV alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "ClamAV alternatives" section above for the current picks, or visit /alternatives/clamav for the full list with editorial commentary on each.
Top EDAForge alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "EDAForge alternatives" section above for the current picks, or visit /alternatives/edaforge for the full list with editorial commentary on each.