# @octokit/endpoint@11.0.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:11:21.000Z
- Files reviewed: 16
- Findings: no findings
- Report: https://security.togoder.click/npm/@octokit/endpoint
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @octokit/endpoint@11.0.2 on Oct 6, 2026. An AI review of 16 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist-bundle/index.js` (safe): The code is a legitimate implementation of the Octokit REST endpoint client, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized process execution.
- `dist-src/defaults.js` (safe): No malicious patterns detected; the file only defines a static configuration object for GitHub API endpoint defaults.
- `dist-src/endpoint-with-defaults.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/merge.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/parse.js` (safe): No malicious patterns detected; the code performs standard request parameter parsing and URL construction for an API client.
- `dist-src/util/add-query-parameters.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/util/extract-url-variable-names.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/util/is-plain-object.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/util/lowercase-keys.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/util/merge-deep.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/util/omit.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/util/remove-undefined-properties.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/util/url-template.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/version.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/with-defaults.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
