Heads up if your CI pipelines are failing right now! 🚨 OSV seems to be experiencing a major wave of false positives over the last few hours, incorrectly flagging massive, highly-trusted packages as malicious.
A few of the biggest casualties so far:
• npm @tanstack/start-storage-context (1.167.4)
• PyPI fastapi (0.136.3)
• PyPI strawberry-graphql (0.315.6)
• npm @nx/key (5.0.7)
If your deployment is bricked, verify manually before panicking. Automation is a tool, not a judge.