Skip to content

Conversation

@HerrMuellerluedenscheid

Hey,

After yet another round of npm compromised packages was reported e.g. here I quick-and-dirtily extended toasted to be able to read from csv.

I saw your support for ioc files which is great. I couldn't find the corresponding files for the previously reported compromised packages but I might not be seasoned enough to search in the right places.

So, what do you think? Is a simple csv input support something that is worth adding? If yes, I will cleanup and rebase on latest main what I have hacked together here.

Cheers

@HerrMuellerluedenscheid

This comment was marked as abuse.

@alex-crabnebula
Copy link

We should at least still provide a local fallback list if a csv (or maybe CVE JSON array?) cannot be found.

@denjell-crabnebula
Copy link
Contributor

Can you please fix your conflicts with the MAIN branch?

@denjell-crabnebula
Copy link
Contributor

@denjell-crabnebula
Copy link
Contributor

denjell-crabnebula commented Sep 17, 2025

Kind of spooky that you have a control sequence buried in the middle of your CSV that you just happened to not put into the codebase. Where did you actually source it from?

mcp-knowESC[48;67;177;2010;2478tledge-graph|1.2.1

[EDIT]: Until we have clarity, marking that comment as abuse.

@HerrMuellerluedenscheid
Copy link
Author

Kind of spooky that you have a control sequence buried in the middle of your CSV that you just happened to not put into the codebase. Where did you actually source it from?

mcp-knowESC[48;67;177;2010;2478tledge-graph|1.2.1

[EDIT]: Until we have clarity, marking that comment as abuse.

Wow!!! I did not see that!! Thanks for having removed the comment! I converted a copy paste from the aforementioned list of npm packages in a, what I thought was a proper formatted csv like table. I will keep this anecdote in my mind as a reminder that it would have been worth the extra 30 seconds effort to convert the table with sed and friends...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants