# @typescript-eslint/typescript-estree@8.70.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:13:28.000Z
- Files reviewed: 43
- Findings: no findings
- Report: https://security.togoder.click/npm/@typescript-eslint/typescript-estree
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @typescript-eslint/typescript-estree@8.70.0 on Oct 6, 2026. An AI review of 43 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/ast-converter.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/check-modifiers.js` (safe): No malicious patterns detected; the code is a standard TypeScript ESLint helper for validating decorators and modifiers, with no network, filesystem, process, or dynamic code execution activity.
- `dist/check-syntax-errors.js` (safe): No malicious patterns detected; the code is a legitimate TypeScript syntax checker that performs static AST validation without network, filesystem, process, or dynamic code execution.
- `dist/clear-caches.js` (safe): No malicious patterns detected
- `dist/convert-comments.js` (safe): This is a standard TypeScript utility file for converting AST comments to ESTree format with no malicious patterns detected.
- `dist/create-program/WatchCompilerHostOfConfigFile.js` (safe): No malicious patterns detected
- `dist/create-program/createIsolatedProgram.js` (safe): No malicious patterns detected; the file is a standard TypeScript/ESLint helper that creates an isolated in-memory TypeScript program and performs no network, filesystem, process, or credential access.
- `dist/create-program/createProjectProgram.js` (safe): No malicious patterns detected; the code is a benign utility for creating TypeScript programs from project settings.
- `dist/create-program/createProjectProgramError.js` (safe): No malicious patterns detected; the code only generates descriptive error messages for TypeScript ESLint configuration issues.
- `dist/create-program/createSourceFile.js` (safe): No malicious patterns detected; the file contains standard TypeScript compiler import shims and a function to create source files for AST parsing.
- `dist/create-program/describeFilePath.js` (safe): No malicious patterns detected; the code only computes and formats file paths relative to a tsconfig root directory using node:path.
- `dist/create-program/getScriptKind.js` (safe): No malicious patterns detected; the file is a standard TypeScript helper for determining script kinds and language variants.
- `dist/create-program/getWatchProgramsForProjects.js` (safe): This is a legitimate TypeScript-ESLint internal module for managing TypeScript watch programs with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning.
- `dist/create-program/shared.js` (safe): No malicious patterns detected; the file contains standard TypeScript helper functions for compiler option and path handling.
- `dist/create-program/useProvidedPrograms.js` (safe): No malicious patterns detected; the file contains standard TypeScript/ESLint helper utilities with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity.
- `dist/create-program/validateDefaultProjectForFilesGlob.js` (safe): No malicious patterns detected; the code only performs input validation on glob patterns and throws errors for overly wide patterns.
- `dist/createParserServices.js` (safe): No malicious patterns detected; the file contains standard TypeScript parser service factory logic with no network, filesystem, process, or dynamic code execution behavior.
- `dist/getImportClausePhaseModifier.js` (safe): No malicious patterns detected; the file contains standard TypeScript compiler API helper code for handling import clause phase modifiers.
- `dist/getModifiers.js` (safe): This is a legitimate TypeScript helper file for retrieving AST node modifiers/decorators with no malicious patterns detected.
- `dist/index.js` (safe): No malicious patterns detected; the code is a standard TypeScript/JavaScript module entry point re-exporting internal modules without any suspicious behavior.
- `dist/jsx/xhtml-entities.js` (safe): No malicious patterns detected; the file only exports a static mapping of XHTML entity names to Unicode characters.
- `dist/node-utils.js` (safe): No malicious patterns detected; the file contains standard TypeScript/ESLint utility functions with no network, filesystem, process execution, or obfuscated code.
- `dist/parseSettings/ExpiringCache.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/parseSettings/candidateTSConfigRootDirs.js` (safe): No malicious patterns detected; the code is a straightforward utility for managing TypeScript config root directories with no network, filesystem, process, or dynamic execution activity.
- `dist/parseSettings/createParseSettings.js` (safe): This is a legitimate TypeScript-ESLint parser settings module with no malicious patterns detected.
- `dist/parseSettings/getProjectConfigFiles.js` (safe): No malicious patterns detected; the file is a standard TypeScript-ESLint utility for locating tsconfig.json files.
- `dist/parseSettings/index.js` (safe): The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns.
- `dist/parseSettings/inferSingleRun.js` (safe): No malicious patterns detected; the code performs benign environment-based detection of ESLint run mode without any data exfiltration, credential harvesting, or dynamic code execution.
- `dist/parseSettings/resolveProjectList.js` (safe): The file is a legitimate TypeScript-ESLint utility for resolving project paths with caching; no malicious patterns were detected.
- `dist/parseSettings/warnAboutTSVersion.js` (safe): No malicious patterns detected; the code is a standard TypeScript version compatibility warning utility with no network, filesystem, process, or obfuscation concerns.
- `dist/parser-options.js` (safe): The file is a minimal compiled TypeScript output that only sets the __esModule marker and references a source map, with no executable, network, filesystem, or obfuscated code.
- `dist/parser.js` (safe): No malicious patterns detected; the code is a standard TypeScript parser module with no exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
- `dist/semantic-or-syntactic-errors.js` (safe): No malicious patterns detected; the file only filters TypeScript diagnostics and converts them to error objects.
- `dist/simple-traverse.js` (safe): No malicious patterns detected; the code is a standard AST traversal utility with no external network, filesystem, process execution, or dynamic code loading.
- `dist/source-files.js` (safe): No malicious patterns detected; the file contains standard TypeScript helper functions and utility exports.
- `dist/ts-estree/estree-to-ts-node-types.js` (safe): No malicious patterns detected
- `dist/ts-estree/index.js` (safe): The code is a standard TypeScript/CommonJS interoperability module with no malicious patterns, network activity, or dynamic execution.
- `dist/ts-estree/ts-nodes.js` (safe): No malicious patterns detected; the file contains only standard TypeScript module boilerplate and a source map reference.
- `dist/use-at-your-own-risk.js` (safe): No malicious patterns detected; the file only contains standard TypeScript compilation helpers and re-exports from internal modules.
- `dist/useProgramFromProjectService.js` (safe): No malicious patterns detected; the file contains standard TypeScript/ESLint project service logic with no data exfiltration, credential harvesting, obfuscation, or process spawning.
- `dist/version-check.js` (safe): No malicious patterns detected; the file is a standard TypeScript/JavaScript version-check utility using semver and typescript imports.
- `dist/version.js` (safe): No malicious patterns detected; the file simply reads the package version from package.json.
- `dist/withoutProjectParserOptions.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
