May 28, 2026 · 28 min · 9 segments
This week Jenn and Paul covered: - **OSV false positives from AWS Inspector:** AWS's automated malware detection pipeline submitted 157 false positive entries to osv.dev. The entries were merged…
Paul McCartyHost
Jenn GileHost
Um, you sent me a link, maybe it was yesterday, maybe it was the day before, about OSV deleted, um, 157 malware entries because they had been found to be false positives.

And, um, I think before we talk about the reaction, I think what we understand, and correct me if I'm wrong here, is there was some kind of LLM generating reports where maybe the, uh, reports were not vetted by a human on the like outgoing side, and then on the incoming side into OSV, maybe nobody at OSV validated them either.

We don't know the exact, you know, exactly what was validated on either side, either from the AWS side or on the OSV side.

There is real harm, uh, when false positives make it into the ecosystem, whether it's vulnerabilities or malware.

I, you know, I s- I said this to a group of my friends on Signal, like I, you know, I really think this is crappy and I'm trying not to say any naughty words because we don't wanna get in trouble, but I think it was really crappy that a bunch of ASPM and AppSec vendors jumped on this.

First, because most of those vendors have never like, kind of, you know, supported, uh, OSV in any way.

And yet many of those vendors, and I'm not gonna use any names, have used OSV as their primary malicious package detection source, you know, since 2023 when they turned it on.

Um, you sent me a link, maybe it was yesterday, maybe it was the day before, about OSV deleted, um, 157 malware entries because they had been found to be false positives.

And, um, I think before we talk about the reaction, I think what we understand, and correct me if I'm wrong here, is there was some kind of LLM generating reports where maybe the, uh, reports were not vetted by a human on the like outgoing side, and then on the incoming side into OSV, maybe nobody at OSV validated them either.

We don't know the exact, you know, exactly what was validated on either side, either from the AWS side or on the OSV side.

There is real harm, uh, when false positives make it into the ecosystem, whether it's vulnerabilities or malware.

I, you know, I s- I said this to a group of my friends on Signal, like I, you know, I really think this is crappy and I'm trying not to say any naughty words because we don't wanna get in trouble, but I think it was really crappy that a bunch of ASPM and AppSec vendors jumped on this.

First, because most of those vendors have never like, kind of, you know, supported, uh, OSV in any way.

And yet many of those vendors, and I'm not gonna use any names, have used OSV as their primary malicious package detection source, you know, since 2023 when they turned it on.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.