Report abuse.
This version was tombstoned
Installing it answers 410. The reason and the full write
history are on the package's public record.
Malicious code, a compromised release, a prompt-injection payload in package docs, name squatting: report it and it gets acted on.
How to report
One email does it. The button prefills the subject and a template; fill in what you found and send.
Handled best effort, no SLA. You get a reply once it is reviewed.
What happens
- A verified report gets the version tombstoned: downloads
answer
410with the reason, and the record stays public as evidence. Nothing is silently erased. - The publishing token is revoked; the audit trail keeps every action.
- Federated packages are mirrored from npmjs, so there are two steps. First, report it to npmjs, where the package actually lives. Then GIVO stops serving the bad cached version on its side.