False Positive OSV Advisories Reported by Amazon Inspector

https://github.com/ossf/malicious-packages/pull/1276/files

Comments

joeyhageMay 26, 2026, 7:23 PM
Currently 46 advisories are being withdrawn. Impacted both pypi and npm dependencies. JFrog Security reported [1] that this caused many bricked deployments.

[1] https://x.com/JFrogSecurity/status/2059188666421940244