Skip to content

Exponential size increase in NPM rules #4343

@AlvaroAMCode

Description

@AlvaroAMCode

Hi,

For weeks now, I have been seeing the size of NPM rules increase dramatically. Week after week, I download the ZIP file all.zip of NPM rules from https://osv-vulnerabilities.storage.googleapis.com/NPM/all.zip and see that the size increases significantly from one week to the next.

Example:

  • 4 November 2025: The ZIP file size is 53,505,950 12 Nov 10:30 all.zip (53,505,950 bytes (≈ 53.5 MB))

  • 12 November 2025: The size is 142,294,351 bytes (≈ 142.3 MB)

The difference is 142,294,351 − 53,505,950 = 88,788,401 bytes (88,788,401 bytes ≈ 84.68 MB)
The new ZIP file is approximately 84.7 MB larger than last week's (1.65 times larger)

I see this week after week. Is it normal for there to be such an increase in NPM rules alone? Could there be duplicates?
This situation is disrupting our scanning behaviour, causing errors and extremely high latencies.

Thank you.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions