Fixed
- Validated fix version now shown in the finding line and verbose table instead of the raw OSV hint, preventing confusing downgrade suggestions.
- Malicious advisory findings (
MAL-*) now surface a clear removal message across all output modes: inline hint in compact,⚠ Maliciousbadge and removal legend in verbose, and⚠ Maliciousbadge with tooltip in the HTML report.
Community Contributions
Thank you for @mcascone for reporting this issue.
Validation
- npm test
- npm run build