Skip to content

Removing FP versions in three npm reports #798

@mgdcvetko

Description

@mgdcvetko

We previously reported these three npm packages and their multiple versions as malicious:

When doing our own research it was concluded that not all reported versions are actually malicious. We would like to update the status on the OSSF repo in accordance with the false positive guide, constitute with removing the non-malicious versions
.
However, the packages in question were removed from npm registry, and it seems it was either hijacked or a malicious actor got hold of it and published a few malicious versions. We'd like to make sure we're on the same page with keeping only the strictly malicious versions in the OSSF advisory, as opposed to leaving them all in.
In this instance we are also not the only reporters, so we may not be able to remove anything at all since it would contradict the GHSA advisory?

Can you please advise us how to proceed?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions