Togoder security

npm package security report

@semantic-release/git npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 11.0.1 Files reviewed 7 Size 8.8 KB Scanned

Summary

Togoder Security scanned the npm package @semantic-release/git@11.0.1 on Oct 6, 2026. An AI review of 7 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
3
low

Findings 4

medium

Command injection risk via argument composition

NPS-B412A5B8ED59

The push function interpolates the branch parameter into a git argument (HEAD:${branch}). If an attacker can control the branch name (e.g. via a branch name returned from a remote or passed through configuration), a crafted value could manipulate git's argument parsing. While execa prevents shell interpretation, git itself has options that can be invoked when arguments begin with -, potentially leading to unexpected behavior such as pushing to unintended refs or executing git hooks.

lib/git.js:71
low

Subprocess execution

NPS-194B4635CFCB

The module invokes the git binary via execa multiple times (ls-files, add, commit, push, rev-parse). Spawning processes is not inherently malicious and is expected for a git library, but it is listed as a category to monitor. No shell strings, backticks, or unsanitized command-line concatenation were found; arguments are passed as arrays, which avoids shell injection.

lib/git.js
low

Parameter passthrough of execaOptions

NPS-F1D51DB512C6

All functions pass caller-supplied execaOptions directly to execa. If an application accepts these options from untrusted input, an attacker could override cwd, env, or shell (e.g., enabling shell: true), which could broaden execution privileges or inject environment variables into the git subprocess. This is a design concern rather than a direct malicious pattern in the source code.

lib/git.js:14
low

Arbitrary file staging via add()

NPS-12567E0D7DB0

The add function accepts a list of files and passes them directly to git add --force --ignore-errors. Since this runs with --force, files explicitly listed in .gitignore are still staged. Combined with the commit and push functions, a caller of this library could stage and push sensitive files (e.g. credentials, .env) inside the repository, though the library itself does not read external files.

lib/git.js:31

Files reviewed

FileVerdictWhat the reviewer saw
lib/git.js medium The module is a thin wrapper around git subprocesses with no exfiltration, credential harvesting, obfuscation, or install-time hooks; minor risks stem from argument passthrough and branch name interpolation that could be abused by callers with untrusted inputs.
index.js safe No malicious patterns detected; the code is a standard semantic-release plugin that validates and prepares Git assets without any suspicious behavior.
lib/definitions/errors.js safe No malicious patterns detected
lib/get-error.js safe Cleared by Jev triage; no further analysis needed
lib/prepare.js safe No malicious patterns detected
lib/resolve-config.js safe Cleared by Jev triage; no further analysis needed
lib/verify.js safe Cleared by Jev triage; no further analysis needed

Scanned versions of @semantic-release/git

VersionVerdictFilesScanned
11.0.1 Needs review 7 Oct 6, 2026

Frequently asked questions

Is @semantic-release/git safe to use?

No confirmed malware was found in @semantic-release/git@11.0.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does @semantic-release/git contain malware?

No malware was identified in @semantic-release/git@11.0.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @semantic-release/git checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @semantic-release/git together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @semantic-release/git@11.0.1, cost nothing.

Related security reports