# git-log-parser@1.2.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:43.000Z
- Files reviewed: 2
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/git-log-parser
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package git-log-parser@1.2.1 on Oct 6, 2026. An AI review of 2 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Spawning processes

Finding ID: `NPS-AECAAE95F812`

File: `src/index.js:34`

The code spawns the 'git' process with 'log' arguments using child_process.spawn. While this is expected functionality for a git log parser package, spawning processes is a potential red flag that warrants attention. The spawned command is hardcoded to 'git' with 'log' subcommand and concatenated arguments, which could be risky if arguments are not properly sanitized.

### [low] Dynamic argument construction

Finding ID: `NPS-E40788A6CACE`

File: `src/index.js:40`

The args() function constructs command-line arguments from a config object using 'argv-formatter'. This could potentially allow injection of malicious git options or flags if the config object is controlled by an attacker, though the scope is limited to git log formatting options.

## Files reviewed

- `src/index.js` (medium): This appears to be a legitimate git log parsing library that spawns git processes to read log data, with no evidence of data exfiltration, credential harvesting, or other malicious behavior.
- `src/fields.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
