Low Security Advisory Detected undefined
Malware — published immediately. Confirmed supply-chain malware is public at publish time and reported concurrently to the affected registry (npm / PyPI / Packagist / …) and the OpenSSF malicious-packages database. There is no coordinated-disclosure window (the maintainer is the attacker). codelake never stores raw payloads — only the detection rule, file:line, and IOCs.
Advisory · CLR-9999-9999

CLR-9999-9999