-= Per source details. Do not edit below this line.=-
The package @rivianlabs/bedrock was found to contain malicious code.
The OpenSSF Package Analysis project identified '@rivianlabs/bedrock' @ 0.0.2 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "be028dadb5642a37a73b040b641fb6070be0adf328c27437477f4c5ddb64ec7a",
"modified_time": "2026-05-05T19:10:36Z",
"versions": [
"0.0.2"
],
"import_time": "2026-05-05T19:36:18.914992079Z",
"source": "ossf-package-analysis"
},
{
"sha256": "7d12061e491ebc9109496b77ffd62384bba9a781ac9f0579343a61c5742df351",
"modified_time": "2026-05-12T06:53:21Z",
"versions": [
"0.0.2"
],
"import_time": "2026-05-12T07:28:50.742545841Z",
"source": "amazon-inspector"
}
]
}