Togoder security

npm package security report

conventional-changelog-writer npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 8.2.0 Files reviewed 14 Size 44.3 KB Scanned

Summary

Togoder Security scanned the npm package conventional-changelog-writer@8.2.0 on Oct 6, 2026. An AI review of 14 source files produced 1 high, 5 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
5
medium
2
low

Findings 8

high

Dynamic code execution via file loading

NPS-09427C2683D8

The --options flag loads a JavaScript object from a user-supplied filepath via loadDataFile(optionsPath). If loadDataFile uses import(), require(), or eval(), this enables arbitrary code execution from a file whose path is controlled by the CLI user or an attacker who can influence arguments. The name 'options' and the meow help text ('a filepath of a javascript object') strongly suggest runtime code loading rather than pure JSON parsing.

dist/cli/index.js:37
medium

External module delegation

NPS-EDFB8AD02869

Core functionality (writeChangelog, loadDataFile, readCommitsFromFiles, readCommitsFromStdin) is imported from '../index.js' and './utils.js', which are not included in this file. The actual behavior of these functions—especially loadDataFile and writeChangelog—cannot be verified from this snippet and could contain the malicious logic described above.

dist/cli/index.js:3
medium

Dynamic code execution via file loading

NPS-DE939873BE56

The --context flag similarly loads data from a user-supplied filepath via loadDataFile(contextPath), which may execute JavaScript if the loader supports non-JSON formats or uses dynamic import/require.

dist/cli/index.js:27
medium

Dynamic import with external input

NPS-55EEFD20AF22

The loadDataFile function dynamically imports a file path provided as input. While it uses pathToFileURL and resolve to convert to a file URL, the path is derived from user-supplied input (filePath). An attacker who controls this argument could potentially load arbitrary JavaScript modules from the file system, leading to code execution. The function is exported and might be called with untrusted data.

dist/cli/utils.js:54
medium

Template injection risk via user-supplied partials

NPS-152DF9A3B8B4

The partials option allows arbitrary Handlebars partials to be registered from external input. Combined with noEscape: true, malicious templates could execute helper logic or inject content. The mainTemplate, headerPartial, commitPartial, and footerPartial options are also fully overridable from caller input.

dist/template.js:59
medium

Unescaped template rendering

NPS-3E71DDD739AC

Handlebars templates are compiled with noEscape: true, disabling HTML escaping. If any commit messages or context data are user-controlled, this could lead to template injection or XSS when the generated changelog is rendered in a browser.

dist/template.js:76
low

Source map inclusion

NPS-B51B3A6899B5

The file includes an inline base64 source map (//# sourceMappingURL=data:application/json;base64,...). While common in build artifacts, source maps can expose original source paths and internal logic; they are not inherently malicious but are noted for completeness.

dist/cli/index.js:66
low

Source map inclusion

NPS-B94C3C105085

The file contains an inline base64-encoded source map comment. Source maps can expose original source code and internal file paths, which may aid attackers in understanding the application structure. While not inherently malicious, it is a security hygiene issue.

dist/cli/utils.js:59

Files reviewed

FileVerdictWhat the reviewer saw
dist/cli/index.js medium The CLI entrypoint appears to be a legitimate changelog writer, but it loads user-specified JavaScript files for context and options, which is a potential arbitrary code execution vector that depends on the unimplemented loadDataFile helper.
dist/cli/utils.js medium The code exhibits a dynamic import vulnerability due to external input, but no clear malicious patterns were found.
dist/template.js medium No malicious patterns found; however, the use of Handlebars with noEscape and externally supplied templates/partials introduces template injection and XSS risks if inputs are untrusted.
dist/commit.js safe No malicious patterns detected; the code only provides a read-only proxy wrapper for commit objects and applies transformation functions.
dist/context.js safe No malicious patterns detected in the context.js file; it contains only pure functions for grouping commits/notes and preparing template context.
dist/index.js safe No malicious patterns detected; the file contains only standard module exports and a source map comment.
dist/options.js safe No malicious patterns detected in the provided options.js file; it contains only benign configuration and data transformation logic.
dist/types/commit.js safe No malicious patterns detected; the file only contains an empty export and a benign base64 source map reference.
dist/types/context.js safe No malicious patterns detected
dist/types/index.js safe The file only re-exports type definitions and contains an inline source map; no malicious patterns were detected.
dist/types/options.js safe The file contains only an empty export statement and an inline source map with no executable code, making it benign.
dist/types/utils.js safe The file is an empty ES module with only a source map comment; no executable or malicious code is present.
dist/utils.js safe No malicious patterns detected; the file contains only benign utility functions for date formatting, safe JSON stringification, and comparator creation.
dist/writers.js safe No malicious patterns detected; the code is a legitimate changelog generation module using standard stream transforms and no risky operations.

Scanned versions of conventional-changelog-writer

VersionVerdictFilesScanned
8.2.0 Needs review 14 Oct 6, 2026

Frequently asked questions

Is conventional-changelog-writer safe to use?

No confirmed malware was found in conventional-changelog-writer@8.2.0, but the review flagged 1 high, 5 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does conventional-changelog-writer contain malware?

No malware was identified in conventional-changelog-writer@8.2.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was conventional-changelog-writer checked?

Togoder Security downloaded the published npm package and had an AI model read its 14 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan conventional-changelog-writer together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in conventional-changelog-writer@8.2.0, cost nothing.

Related security reports