# @sigstore/sign@4.1.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:06.000Z
- Files reviewed: 33
- Findings: 4 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@sigstore/sign
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @sigstore/sign@4.1.1 on Oct 6, 2026. An AI review of 33 source files produced 4 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Environment variable harvesting

Finding ID: `NPS-003974952C10`

File: `dist/identity/ci.js:62`

The code reads process.env.ACTIONS_ID_TOKEN_REQUEST_URL, process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN, and process.env.SIGSTORE_ID_TOKEN. These are CI/CD OIDC token credentials. While this is expected behavior for a Sigstore identity provider, it demonstrates access to sensitive authentication tokens from the environment.

### [medium] Suspicious network request

Finding ID: `NPS-7162404D4765`

File: `dist/identity/ci.js:72`

The getGHAToken function makes an HTTP request to the URL provided by the ACTIONS_ID_TOKEN_REQUEST_URL environment variable, attaching the ACTIONS_ID_TOKEN_REQUEST_TOKEN as a Bearer token in the Authorization header. This transmits the CI token to that URL. In a legitimate GitHub Actions context this URL is GitHub's OIDC endpoint, but the destination is fully controlled by the environment variable.

### [medium] Potential unhandled flow control

Finding ID: `NPS-C19BCA982C58`

File: `dist/signer/fulcio/ca.js:56`

createSigningCertificate calls internalError inside a catch block but does not return or rethrow after invoking it. Depending on the implementation of internalError, execution may continue and attempt to access cert.chain on a possibly undefined cert, or silently proceed with an undefined return value.

### [medium] Undefined variable reference

Finding ID: `NPS-455094CCF49A`

File: `dist/signer/fulcio/ca.js:70`

In toCertificateRequest, the field is assigned 'identity' which is not defined in the function scope. The function parameter is 'identityToken'. This either indicates a typo that will cause a ReferenceError at runtime or references an undeclared global variable, which could silently break certificate signing or mask a deeper bug.

### [low] Network communication

Finding ID: `NPS-CE97D83E3E56`

File: `dist/signer/fulcio/ca.js:30`

The CAClient communicates with a Fulcio certificate authority via a baseURL supplied through options.fulcioBaseURL. This is expected for a signing client but represents external network transmission of a public key and OIDC identity token to a configurable endpoint; if the base URL is attacker-controlled this could leak credentials.

## Files reviewed

- `dist/identity/ci.js` (medium): This appears to be a legitimate Sigstore CIContextProvider that harvests CI OIDC tokens from environment variables and sends them to the environment-specified GitHub Actions token endpoint; the behavior is expected for the package but involves credential handling and network requests that warrant review.
- `dist/signer/fulcio/ca.js` (medium): The file contains no overtly malicious patterns, but has a clear bug (undefined 'identity' variable) and a potential missing return/rethrow in error handling that could cause runtime failures or unintended behavior.
- `dist/bundler/base.js` (safe): No malicious patterns detected; the code is a straightforward base class implementation for signing and witnessing artifacts without any suspicious activities.
- `dist/bundler/bundle.js` (safe): No malicious patterns detected; the file is standard TypeScript bundler helper code for Sigstore bundle assembly with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/bundler/dsse.js` (safe): No malicious patterns detected; the code is a legitimate Sigstore DSSE bundle builder with no exfiltration, credential harvesting, dynamic execution, or process spawning.
- `dist/bundler/index.js` (safe): No malicious patterns detected
- `dist/bundler/message.js` (safe): No malicious patterns detected
- `dist/config.js` (safe): No malicious patterns detected; the code is a legitimate Sigstore configuration module that only constructs signer and witness objects from provided configuration without any exfiltration, obfuscation, or suspicious behavior.
- `dist/error.js` (safe): No malicious patterns detected
- `dist/external/error.js` (safe): No malicious patterns detected
- `dist/external/fetch.js` (safe): No malicious patterns detected; the code is a standard fetch-with-retry utility from the Sigstore project with no exfiltration, credential harvesting, obfuscation, or process spawning.
- `dist/external/fulcio.js` (safe): No malicious patterns detected; the code is a legitimate Fulcio API client for Sigstore that makes expected network requests to a configurable baseURL.
- `dist/external/rekor-v2.js` (safe): No malicious patterns detected; the code is a legitimate Sigstore Rekor v2 API client that only performs expected network requests to a configurable base URL.
- `dist/external/rekor.js` (safe): No malicious patterns detected
- `dist/external/tsa.js` (safe): No malicious patterns detected; the code is a legitimate Sigstore Timestamp Authority client that makes expected network requests for timestamping.
- `dist/identity/index.js` (safe): The file is a simple re-export module from a Sigstore identity package with no malicious patterns, network activity, filesystem access, or dynamic code execution.
- `dist/identity/provider.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): No malicious patterns detected; the file only re-exports public API symbols from internal modules without any suspicious behavior.
- `dist/signer/fulcio/ephemeral.js` (safe): No malicious patterns detected; the code is a legitimate Sigstore ephemeral keypair signer that generates an in-memory P-256 keypair and signs data using Node's crypto module without any exfiltration, obfuscation, or suspicious behavior.
- `dist/signer/fulcio/index.js` (safe): The code implements a legitimate Fulcio certificate signer for sigstore, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation.
- `dist/signer/index.js` (safe): No malicious patterns detected; the file is a simple re-export module for the Sigstore Fulcio signer.
- `dist/signer/signer.js` (safe): No malicious patterns detected
- `dist/types/fetch.js` (safe): No malicious patterns detected
- `dist/util/index.js` (safe): No malicious patterns detected; the file is a standard TypeScript-generated utility module from the Sigstore project that only re-exports modules and contains no suspicious behavior.
- `dist/util/oidc.js` (safe): No malicious patterns detected; the code is a simple utility for extracting the subject from a JWT payload using the @sigstore/core library.
- `dist/util/ua.js` (safe): No malicious patterns detected; the file simply builds a User-Agent string using package version, Node version, and OS platform/arch.
- `dist/witness/index.js` (safe): No malicious patterns detected; the file is a simple module re-export for Sigstore witness utilities.
- `dist/witness/tlog/client.js` (safe): The code is a legitimate Sigstore Rekor transparency log client with no malicious patterns detected.
- `dist/witness/tlog/entry.js` (safe): No malicious patterns detected; the code performs legitimate cryptographic entry formatting for Sigstore/Rekor transparency logs.
- `dist/witness/tlog/index.js` (safe): No malicious patterns detected
- `dist/witness/tsa/client.js` (safe): The code is a legitimate Sigstore TSA client that computes a SHA-256 digest and sends it to a configurable timestamp authority endpoint, with no exfiltration, credential harvesting, obfuscation, or other malicious patterns.
- `dist/witness/tsa/index.js` (safe): No malicious patterns detected; the code is a benign Sigstore TSA witness client that creates RFC3161 timestamps via an external TSA without data exfiltration, credential harvesting, obfuscation, or process/network abuse.
- `dist/witness/witness.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
