False Positives in OSV Vuln Database

OpenSSF’s OSV Vulnerability database has withdrawn 157 false positive reports.

Per Socket’s report, many of the FPs originated from Amazon’s automated VMS.

Many of the withdrawn JSON records point to Amazon Inspector, AWS’s automated vulnerability management service. OpenSSF added Amazon Inspector as an automated source for its malicious-packages repository in October 2025, setting up authentication to an OpenSSF-controlled AWS role that could ingest malicious-package reports from an Amazon Inspector bucket.