# @sigstore/verify@3.1.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:05.000Z
- Files reviewed: 23
- Findings: 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@sigstore/verify
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @sigstore/verify@3.1.1 on Oct 6, 2026. An AI review of 23 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unanchored Regular Expression Matching

Finding ID: `NPS-81D4BB6E9643`

File: `dist/policy.js:11`

verifySubjectAlternativeName uses policyIdentity.match(policyIdentity) without anchoring. If the policyIdentity is user-controlled or constructed from untrusted input, an attacker could craft a pattern that matches unintended signer identities (e.g., 'evil.com' could match 'evil.com.attacker.com'), potentially bypassing certificate identity verification. The comment even warns callers to use anchored patterns, indicating this is a known risk.

### [low] Prototype Pollution in Extension Verification

Finding ID: `NPS-9A433CACB7BA`

File: `dist/policy.js:20`

verifyExtensions iterates over policyExtensions using a for..in loop without hasOwnProperty checks. If policyExtensions inherits from a polluted prototype, it could iterate over inherited properties and cause unexpected behavior or bypass verification. While this file is likely a policy helper rather than an entry point, prototype pollution from other modules could affect behavior here.

## Files reviewed

- `dist/policy.js` (medium): The code is a certificate policy verification utility with no overt malicious patterns, but it uses unanchored regex matching for identity verification and an unguarded for..in loop, which could weaken security guarantees if misused.
- `dist/bundle/dsse.js` (safe): No malicious patterns detected; the code is a benign DSSE signature content handler from the Sigstore project.
- `dist/bundle/index.js` (safe): No malicious patterns detected; the code performs Sigstore bundle parsing and cryptographic verification without suspicious behavior.
- `dist/bundle/message.js` (safe): No malicious patterns detected; the code is a legitimate Sigstore signature verification utility with no exfiltration, obfuscation, or unauthorized execution.
- `dist/error.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): No malicious patterns detected; the file is a standard re-export module from the Sigstore JavaScript client with no obfuscation, network calls, or suspicious execution.
- `dist/key/certificate.js` (safe): No malicious patterns detected
- `dist/key/index.js` (safe): No malicious patterns detected; the code appears to be a legitimate Sigstore verification library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/key/sct.js` (safe): No malicious patterns detected; the code is a legitimate Sigstore SCT verification implementation using standard X.509 certificate processing with no exfiltration, dynamic execution, or credential harvesting.
- `dist/shared.types.js` (safe): No malicious patterns detected
- `dist/timestamp/index.js` (safe): No malicious patterns detected; the code only wraps timestamp verification and formatting without any exfiltration, execution, or filesystem access.
- `dist/timestamp/tsa.js` (safe): No malicious patterns detected; the code implements RFC 3161 timestamp verification using libraries and performs only certificate chain validation.
- `dist/tlog/checkpoint.js` (safe): No malicious patterns detected; the file implements checkpoint verification for Sigstore transparency logs using standard cryptographic operations and input validation.
- `dist/tlog/dsse.js` (safe): No malicious patterns detected; the code is a standard Sigstore DSSE tlog verification module with no network, filesystem, process, or dynamic execution behavior.
- `dist/tlog/hashedrekord.js` (safe): The code is a Sigstore transparency log verification module with no malicious patterns, network calls, process spawning, or obfuscation detected.
- `dist/tlog/index.js` (safe): This is a legitimate Sigstore transparency log verification module with no malicious patterns detected.
- `dist/tlog/intoto.js` (safe): No malicious patterns detected
- `dist/tlog/merkle.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/tlog/set.js` (safe): This is a legitimate Sigstore transparency log SET verification module with no malicious patterns, no external network calls, no credential harvesting, and no dynamic code execution.
- `dist/trust/filter.js` (safe): No malicious patterns detected
- `dist/trust/index.js` (safe): No malicious patterns detected; the code is a standard Sigstore trust material utility with no exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/trust/trust.types.js` (safe): No malicious patterns detected
- `dist/verifier.js` (safe): No malicious patterns detected; the code is a legitimate Sigstore verification library with no data exfiltration, credential harvesting, dynamic code execution, or other security concerns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
