Summary
Togoder Security scanned the npm package @sigstore/protobuf-specs@0.5.1 on Oct 6, 2026. An AI review of 16 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/__generated__/envelope.js | safe | No malicious patterns detected; the file is auto-generated protobuf serialization code with only standard base64/Buffer conversions and no network, filesystem, process, or dynamic execution behavior. |
| dist/__generated__/events.js | safe | This is auto-generated protobuf serialization/deserialization code with no network, filesystem, process, or credential access patterns. |
| dist/__generated__/google/api/field_behavior.js | safe | Auto-generated protobuf TypeScript enum file containing only static enum definitions and JSON conversion functions with no network, filesystem, process, or dynamic execution behavior. |
| dist/__generated__/google/protobuf/any.js | safe | No malicious patterns detected |
| dist/__generated__/google/protobuf/timestamp.js | safe | No malicious patterns detected |
| dist/__generated__/rekor/v2/dsse.js | safe | No malicious patterns detected; the file contains only auto-generated protobuf serialization/deserialization code for Sigstore Rekor DSSE types. |
| dist/__generated__/rekor/v2/entry.js | safe | No malicious patterns detected |
| dist/__generated__/rekor/v2/hashedrekord.js | safe | No malicious patterns detected; the file is auto-generated protobuf serialization/deserialization code with no network, filesystem, process, or dynamic execution behavior. |
| dist/__generated__/rekor/v2/verifier.js | safe | Generated protobuf serialization/deserialization code for Sigstore Rekor verifier types with no malicious patterns detected. |
| dist/__generated__/sigstore_bundle.js | safe | No malicious patterns detected; the file is auto-generated protobuf serialization code with only static, local module imports and pure data transformation functions. |
| dist/__generated__/sigstore_common.js | safe | This is protoc-generated TypeScript/JavaScript code for Sigstore protobuf definitions, containing only enum mappings, JSON serialization helpers, and Base64 conversions with no network, filesystem, process, or dynamic execution behavior. |
| dist/__generated__/sigstore_rekor.js | safe | No malicious patterns detected; this is standard protoc-generated TypeScript serialization code for Sigstore Rekor data structures with only local base64/buffer conversions. |
| dist/__generated__/sigstore_trustroot.js | safe | No malicious patterns detected |
| dist/__generated__/sigstore_verification.js | safe | This is protoc-gen-ts_proto generated code for sigstore verification protobuf types, containing only pure JSON serialization/deserialization logic with no network, filesystem, process, or dynamic code execution patterns. |
| dist/index.js | safe | No malicious patterns detected; the file is a standard TypeScript re-export module with no network, filesystem, process, or dynamic code execution activity. |
| dist/rekor/v2/index.js | safe | No malicious patterns detected; the file is a standard TypeScript/CommonJS re-export barrel for Sigstore Rekor v2 generated modules with only Apache-2.0 licensed code. |
Scanned versions of @sigstore/protobuf-specs
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 0.5.1 | No issues | 16 | Oct 6, 2026 |
Frequently asked questions
Is @sigstore/protobuf-specs safe to use?
Our AI source review of @sigstore/protobuf-specs@0.5.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @sigstore/protobuf-specs contain malware?
No malware was identified in @sigstore/protobuf-specs@0.5.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @sigstore/protobuf-specs checked?
Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @sigstore/protobuf-specs together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @sigstore/protobuf-specs@0.5.1, cost nothing.