# @typescript-eslint/scope-manager@8.70.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:13:23.000Z
- Files reviewed: 178
- Findings: no findings
- Report: https://security.togoder.click/npm/@typescript-eslint/scope-manager
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @typescript-eslint/scope-manager@8.70.0 on Oct 6, 2026. An AI review of 178 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/ID.js` (safe): No malicious patterns detected; the code is a simple in-memory ID generator with no network, filesystem, process, or dynamic execution activity.
- `dist/ScopeManager.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/analyze.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/assert.js` (safe): No malicious patterns detected
- `dist/definition/CatchClauseDefinition.js` (safe): No malicious patterns detected
- `dist/definition/ClassNameDefinition.js` (safe): No malicious patterns detected
- `dist/definition/Definition.js` (safe): No malicious patterns detected
- `dist/definition/DefinitionBase.js` (safe): No malicious patterns detected
- `dist/definition/DefinitionType.js` (safe): No malicious patterns detected
- `dist/definition/FunctionNameDefinition.js` (safe): No malicious patterns detected
- `dist/definition/ImplicitGlobalVariableDefinition.js` (safe): No malicious patterns detected
- `dist/definition/ImportBindingDefinition.js` (safe): No malicious patterns detected
- `dist/definition/ParameterDefinition.js` (safe): No malicious patterns detected
- `dist/definition/TSEnumMemberDefinition.js` (safe): No malicious patterns detected
- `dist/definition/TSEnumNameDefinition.js` (safe): No malicious patterns detected
- `dist/definition/TSModuleNameDefinition.js` (safe): No malicious patterns detected
- `dist/definition/TypeDefinition.js` (safe): This file is a simple TypeScript class definition with no malicious patterns, network activity, file system access, or dynamic code execution.
- `dist/definition/VariableDefinition.js` (safe): No malicious patterns detected
- `dist/definition/index.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): This is a standard TypeScript/CommonJS transpiled module that re-exports functions and types from internal modules, with no malicious patterns detected.
- `dist/lib/base-config.js` (safe): No malicious patterns detected; the file only exports frozen configuration constants generated by Nx.
- `dist/lib/decorators.js` (safe): No malicious patterns detected
- `dist/lib/decorators.legacy.js` (safe): No malicious patterns detected
- `dist/lib/dom.asynciterable.js` (safe): No malicious patterns detected
- `dist/lib/dom.iterable.js` (safe): No malicious patterns detected
- `dist/lib/dom.js` (safe): No malicious patterns detected; this is an auto-generated TypeScript lib configuration file containing only static DOM API type definitions.
- `dist/lib/es2015.collection.js` (safe): No malicious patterns detected; this is an auto-generated TypeScript lib definition file that only exports a static configuration object.
- `dist/lib/es2015.core.js` (safe): This is an auto-generated TypeScript lib definition file that only exports metadata about ES2015 core types, with no malicious patterns or dynamic behavior.
- `dist/lib/es2015.generator.js` (safe): No malicious patterns detected
- `dist/lib/es2015.iterable.js` (safe): No malicious patterns detected; the file is a static auto-generated TypeScript lib declaration mapping with no executable or network code.
- `dist/lib/es2015.js` (safe): No malicious patterns detected; this is a benign auto-generated TypeScript library definition file that only imports and re-exports type information.
- `dist/lib/es2015.promise.js` (safe): No malicious patterns detected; this is a standard auto-generated TypeScript lib definition file for ES2015 Promise with no executable or suspicious code.
- `dist/lib/es2015.proxy.js` (safe): No malicious patterns detected
- `dist/lib/es2015.reflect.js` (safe): No malicious patterns detected; the file is a simple auto-generated TypeScript lib configuration exporting a static object referencing Reflect.
- `dist/lib/es2015.symbol.js` (safe): No malicious patterns detected
- `dist/lib/es2015.symbol.wellknown.js` (safe): This file is an auto-generated TypeScript lib configuration listing standard ES2015 well-known symbol type declarations with no executable or suspicious code.
- `dist/lib/es2016.array.include.js` (safe): No malicious patterns detected in the auto-generated TypeScript library definition file.
- `dist/lib/es2016.full.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib bundle index with static require statements only.
- `dist/lib/es2016.intl.js` (safe): The file is a benign auto-generated TypeScript lib declaration that only re-exports a variable mapping with no executable or suspicious behavior.
- `dist/lib/es2016.js` (safe): No malicious patterns detected; the file is a standard TypeScript-generated library aggregator with no executable or network-related code.
- `dist/lib/es2017.arraybuffer.js` (safe): No malicious patterns detected; the file is a standard auto-generated TypeScript lib declaration for ArrayBuffer.
- `dist/lib/es2017.date.js` (safe): No malicious patterns detected
- `dist/lib/es2017.full.js` (safe): No malicious patterns detected
- `dist/lib/es2017.intl.js` (safe): No malicious patterns detected
- `dist/lib/es2017.js` (safe): No malicious patterns detected; the file is a benign auto-generated TypeScript lib aggregator that only imports sibling modules and exports a static object.
- `dist/lib/es2017.object.js` (safe): No malicious patterns detected
- `dist/lib/es2017.sharedmemory.js` (safe): No malicious patterns detected; this is an auto-generated TypeScript library definition file that only exports static type metadata.
- `dist/lib/es2017.string.js` (safe): No malicious patterns detected
- `dist/lib/es2017.typedarrays.js` (safe): No malicious patterns detected; this is an auto-generated TypeScript lib configuration file that only exports static constructor type references.
- `dist/lib/es2018.asyncgenerator.js` (safe): No malicious patterns detected
- `dist/lib/es2018.asynciterable.js` (safe): No malicious patterns detected
- `dist/lib/es2018.full.js` (safe): No malicious patterns detected
- `dist/lib/es2018.intl.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib configuration with no executable or risky behavior.
- `dist/lib/es2018.js` (safe): No malicious patterns detected
- `dist/lib/es2018.promise.js` (safe): No malicious patterns detected
- `dist/lib/es2018.regexp.js` (safe): No malicious patterns detected; the file is an automatically generated TypeScript lib definition for ES2018 RegExp types with no executable or suspicious code.
- `dist/lib/es2019.array.js` (safe): No malicious patterns detected; this is an auto-generated TypeScript lib configuration file that only declares type references and exports a static object.
- `dist/lib/es2019.full.js` (safe): No malicious patterns detected; the code is a standard TypeScript library definition file that only imports internal modules and exports a configuration object.
- `dist/lib/es2019.intl.js` (safe): No malicious patterns detected
- `dist/lib/es2019.js` (safe): This is an auto-generated TypeScript lib definition aggregator for ES2019, containing only static imports and exports with no malicious patterns.
- `dist/lib/es2019.object.js` (safe): This is an auto-generated TypeScript lib definition file that only exports type metadata, with no executable code or suspicious patterns.
- `dist/lib/es2019.string.js` (safe): This is an auto-generated TypeScript lib definition file containing only a static configuration object with no executable or suspicious code.
- `dist/lib/es2019.symbol.js` (safe): No malicious patterns detected
- `dist/lib/es2020.bigint.js` (safe): No malicious patterns detected
- `dist/lib/es2020.date.js` (safe): No malicious patterns detected
- `dist/lib/es2020.full.js` (safe): This file is an auto-generated TypeScript library definition aggregator with only static require statements and no suspicious behavior.
- `dist/lib/es2020.intl.js` (safe): No malicious patterns detected
- `dist/lib/es2020.js` (safe): No malicious patterns detected
- `dist/lib/es2020.number.js` (safe): No malicious patterns detected
- `dist/lib/es2020.promise.js` (safe): The file is an auto-generated TypeScript lib definition with no executable logic, network access, or suspicious patterns.
- `dist/lib/es2020.sharedmemory.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib definition for ES2020 shared memory types with no executable or suspicious behavior.
- `dist/lib/es2020.string.js` (safe): No malicious patterns detected; this is an auto-generated TypeScript lib definition file that only imports and exports static configuration objects.
- `dist/lib/es2020.symbol.wellknown.js` (safe): No malicious patterns detected
- `dist/lib/es2021.full.js` (safe): This is an auto-generated TypeScript lib definition file that only imports and re-exports standard library configuration objects, with no malicious patterns detected.
- `dist/lib/es2021.intl.js` (safe): This is an auto-generated TypeScript lib definition file with no executable logic or malicious patterns.
- `dist/lib/es2021.js` (safe): This is a benign auto-generated TypeScript lib definition file that only imports and re-exports other ES2021 library modules with no malicious patterns.
- `dist/lib/es2021.promise.js` (safe): No malicious patterns detected
- `dist/lib/es2021.string.js` (safe): No malicious patterns detected
- `dist/lib/es2021.weakref.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript library definition declaring WeakRef and FinalizationRegistry types.
- `dist/lib/es2022.array.js` (safe): No malicious patterns detected
- `dist/lib/es2022.error.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript library definition with static type metadata and standard module imports.
- `dist/lib/es2022.full.js` (safe): This is a standard TypeScript lib definition file that only re-exports references to other compiled TypeScript library modules with no executable, network, filesystem, or process-related logic.
- `dist/lib/es2022.intl.js` (safe): No malicious patterns detected
- `dist/lib/es2022.js` (safe): No malicious patterns detected
- `dist/lib/es2022.object.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib definition with a single require of a local base-config module.
- `dist/lib/es2022.regexp.js` (safe): No malicious patterns detected
- `dist/lib/es2022.string.js` (safe): No malicious patterns detected
- `dist/lib/es2023.array.js` (safe): No malicious patterns detected
- `dist/lib/es2023.collection.js` (safe): No malicious patterns detected
- `dist/lib/es2023.full.js` (safe): No malicious patterns detected; the file is a standard TypeScript lib configuration file that only requires other lib modules and exports a static object.
- `dist/lib/es2023.intl.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript library definition for ES2023 Intl with no executable code beyond a static export.
- `dist/lib/es2023.js` (safe): No malicious patterns detected; the file is a benign auto-generated TypeScript library index that only imports and re-exports related modules.
- `dist/lib/es2024.arraybuffer.js` (safe): No malicious patterns detected
- `dist/lib/es2024.collection.js` (safe): No malicious patterns detected
- `dist/lib/es2024.full.js` (safe): No malicious patterns detected
- `dist/lib/es2024.js` (safe): No malicious patterns detected
- `dist/lib/es2024.object.js` (safe): No malicious patterns detected
- `dist/lib/es2024.promise.js` (safe): No malicious patterns detected
- `dist/lib/es2024.regexp.js` (safe): No malicious patterns detected
- `dist/lib/es2024.sharedmemory.js` (safe): No malicious patterns detected
- `dist/lib/es2024.string.js` (safe): No malicious patterns detected
- `dist/lib/es2025.collection.js` (safe): No malicious patterns detected; this is a standard auto-generated TypeScript lib definition file.
- `dist/lib/es2025.float16.js` (safe): This is a TypeScript auto-generated library definition file declaring Float16Array types, with only static imports and no executable, network, or filesystem logic.
- `dist/lib/es2025.full.js` (safe): No malicious patterns detected
- `dist/lib/es2025.intl.js` (safe): No malicious patterns detected; this is a standard TypeScript lib definition file with no executable or suspicious behavior.
- `dist/lib/es2025.iterator.js` (safe): No malicious patterns detected; the file is a standard TypeScript-generated library definition with no network, filesystem, process, or dynamic code execution behavior.
- `dist/lib/es2025.js` (safe): This is an auto-generated TypeScript lib aggregator file that only imports and re-exports standard ES2025 type definitions with no network, filesystem, process, or dynamic execution behavior.
- `dist/lib/es2025.promise.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib declaration mapping for the PromiseConstructor type with no executable logic, network, filesystem, or process activity.
- `dist/lib/es2025.regexp.js` (safe): This is a simple auto-generated TypeScript lib declaration file with no executable code, network access, file system operations, or suspicious patterns.
- `dist/lib/es5.js` (safe): The file is an auto-generated TypeScript lib configuration defining ES5 type declarations, with no malicious patterns detected.
- `dist/lib/es6.js` (safe): No malicious patterns detected; the file only imports and re-exports TypeScript lib definitions for ES6.
- `dist/lib/es7.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib aggregation module with only static requires and object exports.
- `dist/lib/esnext.array.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib configuration with no executable logic, network access, or process spawning.
- `dist/lib/esnext.asynciterable.js` (safe): No malicious patterns detected
- `dist/lib/esnext.bigint.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib definition with no executable, network, or filesystem activity.
- `dist/lib/esnext.collection.js` (safe): No malicious patterns detected; the file only declares TypeScript/JavaScript library metadata and imports internal configuration modules.
- `dist/lib/esnext.date.js` (safe): No malicious patterns detected; the file is a generated TypeScript lib definition with static imports and object exports only.
- `dist/lib/esnext.decorators.js` (safe): No malicious patterns detected; the file is a generated TypeScript lib configuration that only requires local modules and exports static type definitions.
- `dist/lib/esnext.disposable.js` (safe): This is an auto-generated TypeScript lib definition file that only defines type metadata and re-exports standard library configurations without any malicious patterns.
- `dist/lib/esnext.error.js` (safe): No malicious patterns detected
- `dist/lib/esnext.float16.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib definition with only static require/export declarations.
- `dist/lib/esnext.full.js` (safe): No malicious patterns detected; the file is a generated TypeScript lib aggregator that only requires local modules and exports a static library list.
- `dist/lib/esnext.intl.js` (safe): No malicious patterns detected; the file is a benign auto-generated TypeScript lib definition with no execution, network, or filesystem activity.
- `dist/lib/esnext.iterator.js` (safe): No malicious patterns detected in this auto-generated TypeScript lib definition file.
- `dist/lib/esnext.js` (safe): No malicious patterns detected
- `dist/lib/esnext.object.js` (safe): No malicious patterns detected
- `dist/lib/esnext.promise.js` (safe): No malicious patterns detected
- `dist/lib/esnext.regexp.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib definition exporting a RegExp type reference.
- `dist/lib/esnext.sharedmemory.js` (safe): No malicious patterns detected; the file is a generated TypeScript lib definition that only declares the Atomics variable and imports a base config.
- `dist/lib/esnext.string.js` (safe): No malicious patterns detected; the file is a simple TypeScript lib declaration exporting a string type reference.
- `dist/lib/esnext.symbol.js` (safe): No malicious patterns detected
- `dist/lib/esnext.temporal.js` (safe): No malicious patterns detected; the file is a benign auto-generated TypeScript lib definition with static requires and no side effects.
- `dist/lib/esnext.typedarrays.js` (safe): No malicious patterns detected; the file is a benign TypeScript lib definition for esnext typed arrays.
- `dist/lib/esnext.weakref.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript library definition for WeakRef and FinalizationRegistry with only static metadata and local imports.
- `dist/lib/index.js` (safe): This is a standard TypeScript lib definition mapping file with no executable logic, network calls, or suspicious patterns.
- `dist/lib/lib.js` (safe): No malicious patterns detected; the file is a simple, auto-generated TypeScript lib aggregator with static require statements.
- `dist/lib/scripthost.js` (safe): No malicious patterns detected
- `dist/lib/webworker.asynciterable.js` (safe): No malicious patterns detected
- `dist/lib/webworker.importscripts.js` (safe): No malicious patterns detected; the file is an auto-generated TypeScript lib metadata stub with no executable or suspicious code.
- `dist/lib/webworker.iterable.js` (safe): No malicious patterns detected
- `dist/lib/webworker.js` (safe): No malicious patterns detected
- `dist/referencer/ClassVisitor.js` (safe): No malicious patterns detected
- `dist/referencer/ExportVisitor.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/referencer/ImportVisitor.js` (safe): No malicious patterns detected
- `dist/referencer/PatternVisitor.js` (safe): No malicious patterns detected; this is a standard AST visitor for pattern analysis in @typescript-eslint.
- `dist/referencer/Reference.js` (safe): This is a benign TypeScript compiler helper class with no network, filesystem, process, or dynamic code execution patterns.
- `dist/referencer/Referencer.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/referencer/TypeVisitor.js` (safe): This is a legitimate TypeScript scope-analysis visitor from typescript-eslint with no malicious patterns, network calls, file system access, or credential harvesting.
- `dist/referencer/Visitor.js` (safe): No malicious patterns detected; the file is a standard AST visitor utility with no network, filesystem, process, or dynamic execution behavior.
- `dist/referencer/VisitorBase.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/referencer/index.js` (safe): No malicious patterns detected
- `dist/scope/BlockScope.js` (safe): No malicious patterns detected
- `dist/scope/CatchScope.js` (safe): No malicious patterns detected
- `dist/scope/ClassFieldInitializerScope.js` (safe): The file is a benign ESLint scope definition module that only imports base classes and exports a class constructor; no malicious patterns were detected.
- `dist/scope/ClassScope.js` (safe): No malicious patterns detected
- `dist/scope/ClassStaticBlockScope.js` (safe): No malicious patterns detected; the file is a simple scope class definition with static imports and no dynamic behavior.
- `dist/scope/ConditionalTypeScope.js` (safe): This file defines a simple scope class extending ScopeBase with no malicious patterns, network activity, credential access, or dynamic code execution.
- `dist/scope/ForScope.js` (safe): No malicious patterns detected; the file is a simple scope class definition with no network, filesystem, or dynamic execution behavior.
- `dist/scope/FunctionExpressionNameScope.js` (safe): No malicious patterns detected; this is a standard ESLint scope analysis module defining a function expression name scope.
- `dist/scope/FunctionScope.js` (safe): No malicious patterns detected in the provided TypeScript ESLint scope analysis code.
- `dist/scope/FunctionTypeScope.js` (safe): No malicious patterns detected; the file defines a simple scope class with no network, filesystem, process, or dynamic execution behavior.
- `dist/scope/GlobalScope.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/scope/MappedTypeScope.js` (safe): No malicious patterns detected
- `dist/scope/ModuleScope.js` (safe): No malicious patterns detected
- `dist/scope/Scope.js` (safe): No malicious patterns detected
- `dist/scope/ScopeBase.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/scope/ScopeType.js` (safe): No malicious patterns detected; the file only defines a TypeScript enum of scope types with no executable or suspicious behavior.
- `dist/scope/SwitchScope.js` (safe): No malicious patterns detected
- `dist/scope/TSEnumScope.js` (safe): No malicious patterns detected
- `dist/scope/TSModuleScope.js` (safe): No malicious patterns detected; the file is a simple TypeScript module scope class definition.
- `dist/scope/TypeScope.js` (safe): No malicious patterns detected
- `dist/scope/WithScope.js` (safe): No malicious patterns detected
- `dist/scope/index.js` (safe): No malicious patterns detected
- `dist/variable/ESLintScopeVariable.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/variable/ImplicitLibVariable.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/variable/Variable.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/variable/VariableBase.js` (safe): This file defines a simple VariableBase class with no malicious patterns, external calls, or suspicious behavior.
- `dist/variable/index.js` (safe): No malicious patterns detected; this is a standard barrel file re-exporting modules from @typescript-eslint/scope-manager.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
