Skip to content

Malicious Package Versions Removed from deps.dev #306

@abhisek

Description

@abhisek

It appears if a package is marked as malicious then it is removed from deps.dev including the API.

Example: pkg:/npm/nx@20.12.0 is malicious and shows a 404 on deps.dev site. https://deps.dev/npm/nx/20.12.0

Example: pkg/npm/nx@20.8.0 is not malicious and is shown as expected. https://deps.dev/npm/nx/20.8.0

I have not verified if the malicious package version record is removed from the BigQuery dataset as well or is it a feature of the deps.dev app.

Is this expected behaviour? It seems counterintuitive to have these packages removed from deps.dev which serves as an enriched log / database of open source packages with its associated attributes for various use-cases.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions