# @semantic-release/git@11.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:08.000Z
- Files reviewed: 7
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/@semantic-release/git
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @semantic-release/git@11.0.1 on Oct 6, 2026. An AI review of 7 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Command injection risk via argument composition

Finding ID: `NPS-B412A5B8ED59`

File: `lib/git.js:71`

The `push` function interpolates the `branch` parameter into a git argument (`HEAD:${branch}`). If an attacker can control the branch name (e.g. via a branch name returned from a remote or passed through configuration), a crafted value could manipulate git's argument parsing. While `execa` prevents shell interpretation, git itself has options that can be invoked when arguments begin with `-`, potentially leading to unexpected behavior such as pushing to unintended refs or executing git hooks.

### [low] Subprocess execution

Finding ID: `NPS-194B4635CFCB`

File: `lib/git.js`

The module invokes the `git` binary via `execa` multiple times (`ls-files`, `add`, `commit`, `push`, `rev-parse`). Spawning processes is not inherently malicious and is expected for a git library, but it is listed as a category to monitor. No shell strings, backticks, or unsanitized command-line concatenation were found; arguments are passed as arrays, which avoids shell injection.

### [low] Parameter passthrough of execaOptions

Finding ID: `NPS-F1D51DB512C6`

File: `lib/git.js:14`

All functions pass caller-supplied `execaOptions` directly to `execa`. If an application accepts these options from untrusted input, an attacker could override `cwd`, `env`, or `shell` (e.g., enabling `shell: true`), which could broaden execution privileges or inject environment variables into the git subprocess. This is a design concern rather than a direct malicious pattern in the source code.

### [low] Arbitrary file staging via add()

Finding ID: `NPS-12567E0D7DB0`

File: `lib/git.js:31`

The `add` function accepts a list of `files` and passes them directly to `git add --force --ignore-errors`. Since this runs with `--force`, files explicitly listed in `.gitignore` are still staged. Combined with the `commit` and `push` functions, a caller of this library could stage and push sensitive files (e.g. credentials, `.env`) inside the repository, though the library itself does not read external files.

## Files reviewed

- `lib/git.js` (medium): The module is a thin wrapper around git subprocesses with no exfiltration, credential harvesting, obfuscation, or install-time hooks; minor risks stem from argument passthrough and branch name interpolation that could be abused by callers with untrusted inputs.
- `index.js` (safe): No malicious patterns detected; the code is a standard semantic-release plugin that validates and prepares Git assets without any suspicious behavior.
- `lib/definitions/errors.js` (safe): No malicious patterns detected
- `lib/get-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/prepare.js` (safe): No malicious patterns detected
- `lib/resolve-config.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verify.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
