False Positive Typosquat Alert: package "evg_observable" (Created 4 years ago)
Евгений Гриф
Hello Socket Support Team,
I am writing to appeal a "possible typosquat" flag on my npm package evg_observable (https://socket.dev/npm/package/evg_observable).
This is a clear false positive, and here is why:
Chronology: My package was created 4 years ago. It has a history of 80+ versions. Typosquatting is a technique used for new, malicious packages, not established projects with years of development.
Origin of the name: The "evg" prefix is my personal developer shorthand (Evgeniy), which I use for my projects. It is not an attempt to mimic observable-fns.
The "Competitor" Irony: Ironically, I only learned about the existence of observable-fns because of your alert. I have since added it to my devDependencies specifically to write benchmarks and compare performance, which further proves that my library is a legitimate alternative, not a clone.
Verified Source: The package is linked to my GitHub repository (BarushevEA/light-observable-ts), which has been active for years.
Please review this manually and remove the "Supply Chain Risk" label, as it negatively impacts the reputation of a long-standing open-source project.
Best regards, E.A. Barushev