advisory-database icon indicating copy to clipboard operation
advisory-database copied to clipboard

Request to review GHSA-gwr8-m965-83p4

Open spack-vendavo opened this issue 1 year ago • 2 comments

This demo package was published by an authorized pen tester working with Vendavo, Inc. It was not downloaded by anyone; the pezzi package is only consumed from an internal package manager. The pen tester removed the fake pezzi package, and Vendavo took ownership of the org in npm.

The problem is that this creates false critical alerts in product security scans containing the real pezzi package.

spack-vendavo avatar May 02 '24 13:05 spack-vendavo