Togoder security

npm package security report

@sigstore/protobuf-specs npm package: is it safe?

No malicious code found.

No issues Version 0.5.1 Files reviewed 16 Size 187.2 KB Scanned

Summary

Togoder Security scanned the npm package @sigstore/protobuf-specs@0.5.1 on Oct 6, 2026. An AI review of 16 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
dist/__generated__/envelope.js safe No malicious patterns detected; the file is auto-generated protobuf serialization code with only standard base64/Buffer conversions and no network, filesystem, process, or dynamic execution behavior.
dist/__generated__/events.js safe This is auto-generated protobuf serialization/deserialization code with no network, filesystem, process, or credential access patterns.
dist/__generated__/google/api/field_behavior.js safe Auto-generated protobuf TypeScript enum file containing only static enum definitions and JSON conversion functions with no network, filesystem, process, or dynamic execution behavior.
dist/__generated__/google/protobuf/any.js safe No malicious patterns detected
dist/__generated__/google/protobuf/timestamp.js safe No malicious patterns detected
dist/__generated__/rekor/v2/dsse.js safe No malicious patterns detected; the file contains only auto-generated protobuf serialization/deserialization code for Sigstore Rekor DSSE types.
dist/__generated__/rekor/v2/entry.js safe No malicious patterns detected
dist/__generated__/rekor/v2/hashedrekord.js safe No malicious patterns detected; the file is auto-generated protobuf serialization/deserialization code with no network, filesystem, process, or dynamic execution behavior.
dist/__generated__/rekor/v2/verifier.js safe Generated protobuf serialization/deserialization code for Sigstore Rekor verifier types with no malicious patterns detected.
dist/__generated__/sigstore_bundle.js safe No malicious patterns detected; the file is auto-generated protobuf serialization code with only static, local module imports and pure data transformation functions.
dist/__generated__/sigstore_common.js safe This is protoc-generated TypeScript/JavaScript code for Sigstore protobuf definitions, containing only enum mappings, JSON serialization helpers, and Base64 conversions with no network, filesystem, process, or dynamic execution behavior.
dist/__generated__/sigstore_rekor.js safe No malicious patterns detected; this is standard protoc-generated TypeScript serialization code for Sigstore Rekor data structures with only local base64/buffer conversions.
dist/__generated__/sigstore_trustroot.js safe No malicious patterns detected
dist/__generated__/sigstore_verification.js safe This is protoc-gen-ts_proto generated code for sigstore verification protobuf types, containing only pure JSON serialization/deserialization logic with no network, filesystem, process, or dynamic code execution patterns.
dist/index.js safe No malicious patterns detected; the file is a standard TypeScript re-export module with no network, filesystem, process, or dynamic code execution activity.
dist/rekor/v2/index.js safe No malicious patterns detected; the file is a standard TypeScript/CommonJS re-export barrel for Sigstore Rekor v2 generated modules with only Apache-2.0 licensed code.

Scanned versions of @sigstore/protobuf-specs

VersionVerdictFilesScanned
0.5.1 No issues 16 Oct 6, 2026

Frequently asked questions

Is @sigstore/protobuf-specs safe to use?

Our AI source review of @sigstore/protobuf-specs@0.5.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @sigstore/protobuf-specs contain malware?

No malware was identified in @sigstore/protobuf-specs@0.5.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @sigstore/protobuf-specs checked?

Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @sigstore/protobuf-specs together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @sigstore/protobuf-specs@0.5.1, cost nothing.

Related security reports