Skip to content

@wdp-gov/catalog-serialization-engine not a malware #4783

Open
@sectorxatwork

Description

GHSA-vmh3-vg2w-7g4f
@wdp-gov/catalog-serialization-engine - WDP-GOV is one of the packages used by our dev team. As part of penetration test, we had performed dependency confusion attack via which we had uploaded this malicious package on NPM as part of our security test activity. This packages is being picked up by Mend and have raised alerts across all our scanners. Request github team to please resolve and remove this advisory.

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions