Togoder security

npm package security report

@semantic-release/github npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 12.0.5 Files reviewed 21 Size 58.5 KB Scanned

Summary

Togoder Security scanned the npm package @semantic-release/github@12.0.5 on Oct 6, 2026. An AI review of 21 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
6
low

Findings 8

medium

Import-time side effects

NPS-37E164D3FAA9

The module maintains a module-level mutable state variable 'verified' that is set during verifyConditions and used across publish/addChannel/success/fail. While this file itself does not execute network or filesystem operations at import time, the imported modules (./lib/verify.js, ./lib/publish.js, ./lib/add-channel.js, ./lib/success.js, ./lib/fail.js, ./lib/octokit.js) are not shown and could contain hidden side effects or malicious logic (credential harvesting, exfiltration, etc.). The code should be reviewed alongside those files.

index.js
medium

GitHub token / credential access via Octokit

NPS-CBAD3C3D311A

The plugin conditionally injects an Octokit instance (SemanticReleaseOctokit) and passes it to verify/publish/addChannel/success/fail functions. Octokit instances typically carry GitHub authentication tokens (GH_TOKEN/GITHUB_TOKEN) from the environment. Because the downstream lib files are not provided, there is no visibility into whether these tokens are used only for intended GitHub API calls or potentially exfiltrated. This is a common vector for supply-chain token theft in CI/CD environments.

index.js
low

Configuration merge from other plugin configs

NPS-680692133F80

The verifyConditions function reads the 'publish' plugin configuration and copies fields (assets, successComment, failComment, failTitle, labels, assignees, discussionCategoryName) into pluginConfig. While this mirrors legitimate @semantic-release/github behavior, it allows one plugin's config to influence another's behavior, which could be abused in a compromised dependency chain to inject attacker-controlled values (e.g., labels, comments) into GitHub releases. This is not inherently malicious but warrants scrutiny in context.

index.js:22
low

Dynamic module loading via createRequire

NPS-5004A9F46138

Uses createRequire(import.meta.url) to load package.json at import time. While package.json is loaded from a relative path, createRequire enables arbitrary module resolution and loading which could be abused if the path were influenced. This pattern is common but worth noting.

lib/octokit.js:22
low

Top-level code execution on import

NPS-9D1F87AD4614

Top-level statements read package.json and construct the Octokit plugin class at module load time. This is benign initialization but does execute on import.

lib/octokit.js:24
low

Proxy agent configuration with user input

NPS-3F4054FB5CD2

Proxy agents (HttpProxyAgent, HttpsProxyAgent, ProxyAgent) are constructed from the options.proxy value passed by the caller. If options.proxy is attacker-controlled, requests could be redirected through arbitrary proxies, enabling MITM or data exfiltration. This is a legitimate feature for the package but requires the caller to validate proxy config.

lib/octokit.js:73
low

Network requests with dynamic URLs

NPS-9D7D88BF439D

fetchWithDispatcher sends HTTP requests to caller-supplied URLs (baseUrl / githubApiUrl). This is expected functionality of a GitHub API client, but the dynamic URL construction via urljoin could allow requests to unintended hosts if inputs are attacker-controlled.

lib/octokit.js:78
low

unknown

NPS-D97596670BD0

The function reads sensitive environment variables such as GH_TOKEN, GITHUB_TOKEN and proxy settings. Although this is normal for a config resolver, it could be abused if the resolved config is later logged or sent elsewhere. No exfiltration is present in this file.

lib/resolve-config.js:25

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium This file is the public entry point for what appears to be @semantic-release/github; no direct malicious patterns are present, but it delegates sensitive operations (GitHub API calls with auth tokens) to unreviewed lib/* modules and merges configuration from other plugin configs, so downstream files must be audited to rule out credential exfiltration or supply-chain abuse.
lib/octokit.js medium This is a legitimate GitHub API client wrapper (@semantic-release/github) with no obvious malicious patterns; minor concerns relate to dynamic require, proxy handling, and import-time initialization, all consistent with its intended purpose.
lib/resolve-config.js medium No malicious patterns detected; the file is a normal configuration resolver that reads environment variables but does not exfiltrate or execute untrusted code.
lib/add-channel.js safe No malicious patterns detected; the code is a legitimate semantic-release GitHub plugin that creates or updates GitHub releases using configured credentials.
lib/definitions/constants.js safe Cleared by Jev triage; no further analysis needed
lib/definitions/errors.js safe No malicious patterns detected; the file contains only error message definitions for a semantic-release plugin, using standard Node.js utilities with no network, credential, or process manipulation.
lib/definitions/retry.js safe Cleared by Jev triage; no further analysis needed
lib/definitions/throttle.js safe Cleared by Jev triage; no further analysis needed
lib/fail.js safe No malicious patterns detected; the code is a legitimate semantic-release GitHub plugin that creates issues on release failure.
lib/find-sr-issues.js safe No malicious patterns detected
lib/get-error.js safe Cleared by Jev triage; no further analysis needed
lib/get-fail-comment.js safe Cleared by Jev triage; no further analysis needed
lib/get-release-links.js safe Cleared by Jev triage; no further analysis needed
lib/get-success-comment.js safe Cleared by Jev triage; no further analysis needed
lib/glob-assets.js safe Cleared by Jev triage; no further analysis needed
lib/is-latest-release.js safe Cleared by Jev triage; no further analysis needed
lib/is-prerelease.js safe Cleared by Jev triage; no further analysis needed
lib/parse-github-url.js safe No malicious patterns detected
lib/publish.js safe No malicious patterns detected; this is a legitimate semantic-release GitHub plugin that publishes releases and uploads assets via the GitHub API.
lib/success.js safe No malicious patterns detected; the file is a standard semantic-release GitHub plugin that uses the provided Octokit instance for GitHub API calls and contains no exfiltration, credential harvesting, obfuscation, or shell execution.
lib/verify.js safe No malicious patterns detected; the file contains legitimate configuration validation and GitHub API verification logic for a semantic-release plugin.

Scanned versions of @semantic-release/github

VersionVerdictFilesScanned
12.0.5 Needs review 21 Oct 6, 2026

Frequently asked questions

Is @semantic-release/github safe to use?

No confirmed malware was found in @semantic-release/github@12.0.5, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does @semantic-release/github contain malware?

No malware was identified in @semantic-release/github@12.0.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @semantic-release/github checked?

Togoder Security downloaded the published npm package and had an AI model read its 21 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @semantic-release/github together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @semantic-release/github@12.0.5, cost nothing.

Related security reports