Skip to content

Remove False positive / non-existent package #1036

@divyesh-0x01

Description

@divyesh-0x01

Hi Team,

The advisory released in last June, was False Positive as it was created for test purpose with no actual malicious code, and later was removed from npm. Since, the package does not exist in public npm anymore, rather in private repo, can this be removed to avoid flagging for the false positive alert.

The advisories are

Reference links -
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/%40wdpx/themes/MAL-2024-1641.json
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/%40wdp-gov/catalog-serialization-engine/MAL-2024-1668.json
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/%40wdp-gov/lineage-component/MAL-2024-1667.json

Kindly withdraw these alerts as they are non-existent now and were false positive when raised.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions