The package monorepo-symlink-test currently has version 0.0.1-security which is a placeholder for the previously removed package on npm registry. This is being reported as malware via GHSA-2jcg-qqmg-46q6 which is a false positive.
It would be good to exclude the 0.0.1-security placeholder version from the advisory.
The package monorepo-symlink-test currently has version 0.0.1-security which is a placeholder for the previously removed package on npm registry. This is being reported as malware via GHSA-2jcg-qqmg-46q6 which is a false positive.
It would be good to exclude the 0.0.1-security placeholder version from the advisory.