-
Notifications
You must be signed in to change notification settings - Fork 261
Description
Hi,
For weeks now, I have been seeing the size of NPM rules increase dramatically. Week after week, I download the ZIP file all.zip of NPM rules from https://osv-vulnerabilities.storage.googleapis.com/NPM/all.zip and see that the size increases significantly from one week to the next.
Example:
-
4 November 2025: The ZIP file size is 53,505,950 12 Nov 10:30 all.zip (53,505,950 bytes (≈ 53.5 MB))
-
12 November 2025: The size is 142,294,351 bytes (≈ 142.3 MB)
The difference is 142,294,351 − 53,505,950 = 88,788,401 bytes (88,788,401 bytes ≈ 84.68 MB)
The new ZIP file is approximately 84.7 MB larger than last week's (1.65 times larger)
I see this week after week. Is it normal for there to be such an increase in NPM rules alone? Could there be duplicates?
This situation is disrupting our scanning behaviour, causing errors and extremely high latencies.
Thank you.