A security tool that never publishes its mistakes is asking to be taken on faith. This page is the opposite of that: every verdict we published and later corrected, what went wrong, and what we changed so it would not happen again.
No dispute has been upheld to date.
Read that precisely. It means nobody has reported a verdict of ours as wrong and been
proven right yet. It is not a claim that our verdicts have all been correct, and you should not
treat it as one. This is a young service with modest volume, detection is imperfect by nature, and a
clear result can be wrong. An unbroken record is not something we could prove even if we had one,
so it is not something we claim.
If you publish an artifact and believe our malicious or flagged verdict is wrong,
email contact@lazaretto.dev with the package or hash. Our commitment,
which is referenced from the Terms:
malicious verdict within three business days.Corrections are the last line, not the first. We also say up front where a verdict is
weaker than it looks: a scan that could not read part of an artifact says so, a known-bad check that could
not run reports null rather than "no match", and an unpinned package with a version-scoped advisory
returns "cannot determine" rather than a guess. See where our data comes from
and the disclaimer.
Machine-readable: /corrections.json