OpenSSF’s OSV Vulnerability database has withdrawn 157 false positive reports.
Per Socket’s report, many of the FPs originated from Amazon’s automated VMS.
Many of the withdrawn JSON records point to Amazon Inspector, AWS’s automated vulnerability management service. OpenSSF added Amazon Inspector as an automated source for its
malicious-packagesrepository in October 2025, setting up authentication to an OpenSSF-controlled AWS role that could ingest malicious-package reports from an Amazon Inspector bucket.