Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This advisory is a GitHub malware report against a public npm registry package, published with an unbounded >= 0 affected range and no fixed version; that registry name is now a security-holding placeholder whose only surviving release is 0.0.1-security, and the flagged 2.0.0 never existed there. The detection comes from the scanner reading the name and version fields of a first-party webapp module manifest that is built from source and never installed from the registry, so the identifier collides with the advisory subject rather than matching it. The shipped artifact contains no node_modules tree and no dependency of that name.
Status