Togoder security

npm package security report

@sigstore/sign npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 4.1.1 Files reviewed 33 Size 65.8 KB Scanned

Summary

Togoder Security scanned the npm package @sigstore/sign@4.1.1 on Oct 6, 2026. An AI review of 33 source files produced 4 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
1
low

Findings 5

medium

Environment variable harvesting

NPS-003974952C10

The code reads process.env.ACTIONS_ID_TOKEN_REQUEST_URL, process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN, and process.env.SIGSTORE_ID_TOKEN. These are CI/CD OIDC token credentials. While this is expected behavior for a Sigstore identity provider, it demonstrates access to sensitive authentication tokens from the environment.

dist/identity/ci.js:62
medium

Suspicious network request

NPS-7162404D4765

The getGHAToken function makes an HTTP request to the URL provided by the ACTIONS_ID_TOKEN_REQUEST_URL environment variable, attaching the ACTIONS_ID_TOKEN_REQUEST_TOKEN as a Bearer token in the Authorization header. This transmits the CI token to that URL. In a legitimate GitHub Actions context this URL is GitHub's OIDC endpoint, but the destination is fully controlled by the environment variable.

dist/identity/ci.js:72
medium

Potential unhandled flow control

NPS-C19BCA982C58

createSigningCertificate calls internalError inside a catch block but does not return or rethrow after invoking it. Depending on the implementation of internalError, execution may continue and attempt to access cert.chain on a possibly undefined cert, or silently proceed with an undefined return value.

dist/signer/fulcio/ca.js:56
medium

Undefined variable reference

NPS-455094CCF49A

In toCertificateRequest, the field is assigned 'identity' which is not defined in the function scope. The function parameter is 'identityToken'. This either indicates a typo that will cause a ReferenceError at runtime or references an undeclared global variable, which could silently break certificate signing or mask a deeper bug.

dist/signer/fulcio/ca.js:70
low

Network communication

NPS-CE97D83E3E56

The CAClient communicates with a Fulcio certificate authority via a baseURL supplied through options.fulcioBaseURL. This is expected for a signing client but represents external network transmission of a public key and OIDC identity token to a configurable endpoint; if the base URL is attacker-controlled this could leak credentials.

dist/signer/fulcio/ca.js:30

Files reviewed

FileVerdictWhat the reviewer saw
dist/identity/ci.js medium This appears to be a legitimate Sigstore CIContextProvider that harvests CI OIDC tokens from environment variables and sends them to the environment-specified GitHub Actions token endpoint; the behavior is expected for the package but involves credential handling and network requests that warrant review.
dist/signer/fulcio/ca.js medium The file contains no overtly malicious patterns, but has a clear bug (undefined 'identity' variable) and a potential missing return/rethrow in error handling that could cause runtime failures or unintended behavior.
dist/bundler/base.js safe No malicious patterns detected; the code is a straightforward base class implementation for signing and witnessing artifacts without any suspicious activities.
dist/bundler/bundle.js safe No malicious patterns detected; the file is standard TypeScript bundler helper code for Sigstore bundle assembly with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/bundler/dsse.js safe No malicious patterns detected; the code is a legitimate Sigstore DSSE bundle builder with no exfiltration, credential harvesting, dynamic execution, or process spawning.
dist/bundler/index.js safe No malicious patterns detected
dist/bundler/message.js safe No malicious patterns detected
dist/config.js safe No malicious patterns detected; the code is a legitimate Sigstore configuration module that only constructs signer and witness objects from provided configuration without any exfiltration, obfuscation, or suspicious behavior.
dist/error.js safe No malicious patterns detected
dist/external/error.js safe No malicious patterns detected
dist/external/fetch.js safe No malicious patterns detected; the code is a standard fetch-with-retry utility from the Sigstore project with no exfiltration, credential harvesting, obfuscation, or process spawning.
dist/external/fulcio.js safe No malicious patterns detected; the code is a legitimate Fulcio API client for Sigstore that makes expected network requests to a configurable baseURL.
dist/external/rekor-v2.js safe No malicious patterns detected; the code is a legitimate Sigstore Rekor v2 API client that only performs expected network requests to a configurable base URL.
dist/external/rekor.js safe No malicious patterns detected
dist/external/tsa.js safe No malicious patterns detected; the code is a legitimate Sigstore Timestamp Authority client that makes expected network requests for timestamping.
dist/identity/index.js safe The file is a simple re-export module from a Sigstore identity package with no malicious patterns, network activity, filesystem access, or dynamic code execution.
dist/identity/provider.js safe No malicious patterns detected
dist/index.js safe No malicious patterns detected; the file only re-exports public API symbols from internal modules without any suspicious behavior.
dist/signer/fulcio/ephemeral.js safe No malicious patterns detected; the code is a legitimate Sigstore ephemeral keypair signer that generates an in-memory P-256 keypair and signs data using Node's crypto module without any exfiltration, obfuscation, or suspicious behavior.
dist/signer/fulcio/index.js safe The code implements a legitimate Fulcio certificate signer for sigstore, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation.
dist/signer/index.js safe No malicious patterns detected; the file is a simple re-export module for the Sigstore Fulcio signer.
dist/signer/signer.js safe No malicious patterns detected
dist/types/fetch.js safe No malicious patterns detected
dist/util/index.js safe No malicious patterns detected; the file is a standard TypeScript-generated utility module from the Sigstore project that only re-exports modules and contains no suspicious behavior.
dist/util/oidc.js safe No malicious patterns detected; the code is a simple utility for extracting the subject from a JWT payload using the @sigstore/core library.
Show 8 more files
FileVerdictWhat the reviewer saw
dist/util/ua.js safe No malicious patterns detected; the file simply builds a User-Agent string using package version, Node version, and OS platform/arch.
dist/witness/index.js safe No malicious patterns detected; the file is a simple module re-export for Sigstore witness utilities.
dist/witness/tlog/client.js safe The code is a legitimate Sigstore Rekor transparency log client with no malicious patterns detected.
dist/witness/tlog/entry.js safe No malicious patterns detected; the code performs legitimate cryptographic entry formatting for Sigstore/Rekor transparency logs.
dist/witness/tlog/index.js safe No malicious patterns detected
dist/witness/tsa/client.js safe The code is a legitimate Sigstore TSA client that computes a SHA-256 digest and sends it to a configurable timestamp authority endpoint, with no exfiltration, credential harvesting, obfuscation, or other malicious patterns.
dist/witness/tsa/index.js safe No malicious patterns detected; the code is a benign Sigstore TSA witness client that creates RFC3161 timestamps via an external TSA without data exfiltration, credential harvesting, obfuscation, or process/network abuse.
dist/witness/witness.js safe No malicious patterns detected

Scanned versions of @sigstore/sign

VersionVerdictFilesScanned
4.1.1 Needs review 33 Oct 6, 2026

Frequently asked questions

Is @sigstore/sign safe to use?

No confirmed malware was found in @sigstore/sign@4.1.1, but the review flagged 4 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @sigstore/sign contain malware?

No malware was identified in @sigstore/sign@4.1.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @sigstore/sign checked?

Togoder Security downloaded the published npm package and had an AI model read its 33 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @sigstore/sign together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @sigstore/sign@4.1.1, cost nothing.

Related security reports