# orval@8.39.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:41.000Z
- Files reviewed: 6
- Findings: 1 medium, 7 low severity findings
- Report: https://security.togoder.click/npm/orval
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package orval@8.39.0 on Oct 6, 2026. An AI review of 6 source files produced 1 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] dynamic import

Finding ID: `NPS-4C67384F511E`

File: `dist/index.mjs:4`

The generate function uses a dynamic import() to load a local module ('./generate-Tb6cDX2C.mjs') at call time. While the path is static and relative, dynamic imports can be used to obfuscate code and delay execution, making static analysis harder. This is not inherently malicious but warrants review of the imported module.

### [low] File system manipulation

Finding ID: `NPS-F43104C45667`

File: `dist/barrel-D9EU9nTw.mjs`

The code reads and writes barrel files (index files with re-exports) using fs and writeGeneratedFile from @orval/core. Operations are limited to the file paths provided as arguments (e.g., indexFile, filePath) and their sibling directories. No sensitive paths like ~/.ssh, ~/.npmrc, or environment variables are accessed.

### [low] Path resolution from specifiers

Finding ID: `NPS-1B8BA0A356CE`

File: `dist/barrel-D9EU9nTw.mjs:14`

reExportSpecifierExists resolves relative specifiers against the directory of the index file and checks candidate files. This is standard module resolution logic and does not traverse outside the project structure based on untrusted input.

### [low] re-export from external dependency

Finding ID: `NPS-9FD756A69CDD`

File: `dist/index.mjs:2`

The file re-exports everything from '@orval/core'. This could expose additional functions from the dependency, but does not itself introduce malicious behavior. Still, it increases the attack surface if the dependency is compromised.

### [low] Network request

Finding ID: `NPS-E9B96881E985`

File: `dist/options-BazNQK7L.mjs`

The code performs HEAD/GET requests to user-provided input URLs (with 10s timeout) to validate targets. This is expected behavior for a code generator that can fetch remote OpenAPI specs; no exfiltration of local data is present.

### [low] Dynamic import

Finding ID: `NPS-9D23B8D15154`

File: `dist/options-BazNQK7L.mjs`

Uses dynamicImport for local package.json files and a static import('@orval/mock'). No computed/external attacker-controlled module loading is observed.

### [low] File system access

Finding ID: `NPS-725B7FA3476C`

File: `dist/options-BazNQK7L.mjs`

Reads package.json, tsconfig.json, pnpm-workspace.yaml, .yarnrc.yml from the workspace and walks to filesystem root. This is normal configuration discovery, not credential harvesting.

### [low] Module resolution

Finding ID: `NPS-CE17C788C8D8`

File: `dist/options-BazNQK7L.mjs`

Uses createRequire to resolve package specifiers from the workspace, which is expected for resolving mutators/schemas imports.

## Files reviewed

- `dist/index.mjs` (medium): The file uses dynamic import and re-exports from a dependency; while no clear malicious patterns are present, the delayed module loading deserves closer inspection of the imported file.
- `dist/barrel-D9EU9nTw.mjs` (safe): The code performs legitimate barrel file reconciliation for generated re-exports, with no exfiltration, credential harvesting, obfuscation, or malicious execution patterns.
- `dist/bin/orval.mjs` (safe): No malicious patterns detected
- `dist/generate-Tb6cDX2C.mjs` (safe): No malicious patterns detected; the code is a standard Orval API generation module that uses expected library imports and performs no suspicious network, filesystem, credential, or process operations.
- `dist/options-BazNQK7L.mjs` (safe): No malicious patterns detected; the code is a legitimate orval configuration/options normalization module with expected network, filesystem, and dynamic-import usage.
- `dist/write-zod-specs-BWwpK_l2.mjs` (safe): The file is a legitimate orval code-generation module that transforms OpenAPI schemas into Zod validation code, with no exfiltration, process spawning, dynamic code execution, credential harvesting, or other malicious patterns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
