-= Per source details. Do not edit below this line.=-
The package dunnhumby-component-library was found to contain malicious code.
The OpenSSF Package Analysis project identified 'dunnhumby-component-library' @ 1.1.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "6da13423e5cb44ae4cf9803a0d05a8827cba013c92c5689216dd8a0f3b3e4d43",
"source": "ossf-package-analysis",
"modified_time": "2025-11-05T13:51:10Z",
"import_time": "2025-11-05T14:06:28.680546183Z",
"versions": [
"1.1.0"
]
},
{
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"source": "amazon-inspector",
"modified_time": "2025-11-09T00:17:09Z",
"sha256": "8b047f32f0323beace719a36eec364b2d804d556202950dae7942b04e2f2b09a",
"import_time": "2025-11-09T00:27:26.112190251Z"
}
]
}