-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'claude-code-base-action' @ 2.0.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "f08c76c834d5f7c2ce735d4dd85684ec34f3dcc29e1353dc7633fb72ee79aaaf",
"import_time": "2026-05-17T15:26:55.54141334Z",
"modified_time": "2026-05-17T15:19:44Z",
"versions": [
"2.0.0"
],
"source": "ossf-package-analysis"
},
{
"sha256": "3c9e36883f6e538eda86eb64854165d767b96458a12405a7ccd967c8015f6269",
"import_time": "2026-05-17T15:50:45.342577666Z",
"modified_time": "2026-05-17T15:41:36Z",
"versions": [
"2.2.2"
],
"source": "ossf-package-analysis"
}
]
}