# fast-glob@3.3.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:11:19.000Z
- Files reviewed: 26
- Findings: no findings
- Report: https://security.togoder.click/npm/fast-glob
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package fast-glob@3.3.1 on Oct 6, 2026. An AI review of 26 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `out/index.js` (safe): No malicious patterns detected; the file is a legitimate globbing library entry point with no network, process, or filesystem abuse.
- `out/managers/tasks.js` (safe): No malicious patterns detected
- `out/providers/async.js` (safe): No malicious patterns detected; the code is a straightforward async provider implementation that reads directory entries and transforms them without any external network, credential, process, or obfuscation concerns.
- `out/providers/filters/deep.js` (safe): Cleared by Jev triage; no further analysis needed
- `out/providers/filters/entry.js` (safe): Cleared by Jev triage; no further analysis needed
- `out/providers/filters/error.js` (safe): No malicious patterns detected
- `out/providers/matchers/matcher.js` (safe): Cleared by Jev triage; no further analysis needed
- `out/providers/matchers/partial.js` (safe): No malicious patterns detected; the code is a benign glob/path pattern matcher implementation with no network, filesystem, process, or dynamic execution behavior.
- `out/providers/provider.js` (safe): No malicious patterns detected
- `out/providers/stream.js` (safe): Cleared by Jev triage; no further analysis needed
- `out/providers/sync.js` (safe): No malicious patterns detected; the code is a straightforward provider synchronizer that reads local directory entries.
- `out/providers/transformers/entry.js` (safe): Cleared by Jev triage; no further analysis needed
- `out/readers/async.js` (safe): Cleared by Jev triage; no further analysis needed
- `out/readers/reader.js` (safe): No malicious patterns detected; the code is a standard filesystem reader utility without network, process execution, or credential access.
- `out/readers/stream.js` (safe): Cleared by Jev triage; no further analysis needed
- `out/readers/sync.js` (safe): This is a benign synchronous file system reader utility with no malicious patterns, external network calls, or suspicious behavior.
- `out/settings.js` (safe): No malicious patterns detected
- `out/types/index.js` (safe): No malicious patterns detected
- `out/utils/array.js` (safe): No malicious patterns detected
- `out/utils/errno.js` (safe): No malicious patterns detected
- `out/utils/fs.js` (safe): No malicious patterns detected; the code only wraps Node.js fs.Stats methods into a Dirent-like object with no I/O, network, or dynamic execution.
- `out/utils/index.js` (safe): No malicious patterns detected; the file only re-exports internal utility modules with no network, process, or filesystem access.
- `out/utils/path.js` (safe): No malicious patterns detected; the code only performs path manipulation and escaping using standard Node.js modules.
- `out/utils/pattern.js` (safe): No malicious patterns detected
- `out/utils/stream.js` (safe): No malicious patterns detected
- `out/utils/string.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
