# Known-bad / denylisted package identifiers. Format: one entry per line, either # a bare name (any version) or name@version for a specific pinned bad release. # This is a LOCAL denylist used when no live CVE/OSV scanner is available; a real # deployment should also run npm audit / pip-audit / osv-scanner (the gate runs # them when present and records tool availability in the report). # # The entries below are illustrative fixtures (documented malware families / # typosquat campaigns) so the gate has deterministic denials to test against. event-stream@3.3.6 flatmap-stream coa@2.0.3 rc@1.2.9 ua-parser-js@0.7.29 node-ipc@10.1.1 colors@1.4.44-liberty-2 crossenv cross-env.js