# @typescript-eslint/project-service@8.70.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:13:13.000Z
- Files reviewed: 3
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/@typescript-eslint/project-service
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @typescript-eslint/project-service@8.70.0 on Oct 6, 2026. An AI review of 3 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Dynamic require

Finding ID: `NPS-D410AEDF538A`

File: `dist/createProjectService.js:61`

The code uses require('typescript/lib/tsserverlibrary') lazily inside the function. While this is dynamic module loading, the module path is hardcoded and legitimate (TypeScript's tsserverlibrary). No external input influences the module path, so it's not a security concern.

### [low] Performance API usage

Finding ID: `NPS-62843B23AC9C`

File: `dist/createProjectService.js:131`

Uses performance.now() which is a standard web/Node.js timing API, not a security concern.

## Files reviewed

- `dist/createProjectService.js` (safe): No malicious patterns detected; the code is a legitimate TypeScript ESLint project service implementation with only benign dynamic module loading and standard API usage.
- `dist/getParsedConfigFileFromTSServer.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): No malicious patterns detected; the file only contains standard TypeScript helper functions and re-exports a local module.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
