ossf / malicious-packages

A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
Apache License 2.0
231 stars 21 forks source link

Improve package name handling and remove self refs. #477

Closed calebbrown closed 4 months ago

calebbrown commented 5 months ago

This change improves how package names are handled and ensures that any self-references in Aliases or References are removed (e.g. if MAL-2024-123 appears in the Aliases for the report with the id MAL-2024-123, it is removed)