Posted by ezraax on Sep 23 Hi, Sharing a registry-metadata observation that matters for supply-chain incident response. I audited npm's public package documents and found a retention asymmetry. Each package document has a `time` map (per-version publish stamps) and a `versions` map (the manifests).
npm registry keeps removed-version timestamps but drops the reason (Sept 2025 campaign as evidence)
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/887
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.





