Browsing: OSV

A malware package advisory pipeline must preserve original evidence, verify provenance, identify affected versions, and issue auditable decisions. When an advisory is incorrect or withdrawn, create a correction event and switch the active snapshot instead of deleting history.