# @sigstore/protobuf-specs@0.5.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:01.000Z
- Files reviewed: 16
- Findings: no findings
- Report: https://security.togoder.click/npm/@sigstore/protobuf-specs
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @sigstore/protobuf-specs@0.5.1 on Oct 6, 2026. An AI review of 16 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/__generated__/envelope.js` (safe): No malicious patterns detected; the file is auto-generated protobuf serialization code with only standard base64/Buffer conversions and no network, filesystem, process, or dynamic execution behavior.
- `dist/__generated__/events.js` (safe): This is auto-generated protobuf serialization/deserialization code with no network, filesystem, process, or credential access patterns.
- `dist/__generated__/google/api/field_behavior.js` (safe): Auto-generated protobuf TypeScript enum file containing only static enum definitions and JSON conversion functions with no network, filesystem, process, or dynamic execution behavior.
- `dist/__generated__/google/protobuf/any.js` (safe): No malicious patterns detected
- `dist/__generated__/google/protobuf/timestamp.js` (safe): No malicious patterns detected
- `dist/__generated__/rekor/v2/dsse.js` (safe): No malicious patterns detected; the file contains only auto-generated protobuf serialization/deserialization code for Sigstore Rekor DSSE types.
- `dist/__generated__/rekor/v2/entry.js` (safe): No malicious patterns detected
- `dist/__generated__/rekor/v2/hashedrekord.js` (safe): No malicious patterns detected; the file is auto-generated protobuf serialization/deserialization code with no network, filesystem, process, or dynamic execution behavior.
- `dist/__generated__/rekor/v2/verifier.js` (safe): Generated protobuf serialization/deserialization code for Sigstore Rekor verifier types with no malicious patterns detected.
- `dist/__generated__/sigstore_bundle.js` (safe): No malicious patterns detected; the file is auto-generated protobuf serialization code with only static, local module imports and pure data transformation functions.
- `dist/__generated__/sigstore_common.js` (safe): This is protoc-generated TypeScript/JavaScript code for Sigstore protobuf definitions, containing only enum mappings, JSON serialization helpers, and Base64 conversions with no network, filesystem, process, or dynamic execution behavior.
- `dist/__generated__/sigstore_rekor.js` (safe): No malicious patterns detected; this is standard protoc-generated TypeScript serialization code for Sigstore Rekor data structures with only local base64/buffer conversions.
- `dist/__generated__/sigstore_trustroot.js` (safe): No malicious patterns detected
- `dist/__generated__/sigstore_verification.js` (safe): This is protoc-gen-ts_proto generated code for sigstore verification protobuf types, containing only pure JSON serialization/deserialization logic with no network, filesystem, process, or dynamic code execution patterns.
- `dist/index.js` (safe): No malicious patterns detected; the file is a standard TypeScript re-export module with no network, filesystem, process, or dynamic code execution activity.
- `dist/rekor/v2/index.js` (safe): No malicious patterns detected; the file is a standard TypeScript/CommonJS re-export barrel for Sigstore Rekor v2 generated modules with only Apache-2.0 licensed code.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
