# glob@13.0.6 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:13.000Z
- Files reviewed: 14
- Findings: no findings
- Report: https://security.togoder.click/npm/glob
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package glob@13.0.6 on Oct 6, 2026. An AI review of 14 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/commonjs/glob.js` (safe): This is a standard glob pattern matching library implementation with no malicious patterns detected.
- `dist/commonjs/has-magic.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/commonjs/ignore.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/commonjs/index.js` (safe): No malicious patterns detected; the file is a standard re-export and API wrapper for the glob package.
- `dist/commonjs/pattern.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/commonjs/processor.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/commonjs/walker.js` (safe): No malicious patterns detected; the code is a legitimate glob-walking utility with no network, credential, or command-execution activity.
- `dist/esm/glob.js` (safe): No malicious patterns detected; the code is a legitimate glob traversal utility with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `dist/esm/has-magic.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/ignore.js` (safe): No malicious patterns detected; the code implements gitignore-style pattern matching using minimatch with standard configuration.
- `dist/esm/index.js` (safe): No malicious patterns detected; this is the standard ESM entry point for the glob package re-exporting APIs from internal modules and minimatch.
- `dist/esm/pattern.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/processor.js` (safe): No malicious patterns detected; the code is a legitimate glob pattern processor from minimatch with no data exfiltration, obfuscation, process spawning, or suspicious network/file system activity.
- `dist/esm/walker.js` (safe): No malicious patterns detected; the code is a standard glob walker utility with no network, credential, or process execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
