# victory-vendor@37.3.6 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:25:20.000Z
- Files reviewed: 276
- Findings: no findings
- Report: https://security.togoder.click/npm/victory-vendor
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package victory-vendor@37.3.6 on Oct 6, 2026. An AI review of 276 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `d3-array.js` (safe): Cleared by Jev triage; no further analysis needed
- `d3-ease.js` (safe): Cleared by Jev triage; no further analysis needed
- `d3-interpolate.js` (safe): Cleared by Jev triage; no further analysis needed
- `d3-scale.js` (safe): Cleared by Jev triage; no further analysis needed
- `d3-shape.js` (safe): Cleared by Jev triage; no further analysis needed
- `d3-time.js` (safe): Cleared by Jev triage; no further analysis needed
- `d3-timer.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-array.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-color.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-ease.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-format.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-interpolate.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-path.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-scale.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-shape.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-time-format.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-time.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-timer.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/d3-voronoi.js` (safe): Cleared by Jev triage; no further analysis needed
- `es/internmap.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib-vendor/d3-array/src/array.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/ascending.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/bin.js` (safe): No malicious patterns detected; the file is a legitimate D3.js histogram binning implementation with standard module imports and no suspicious behavior.
- `lib-vendor/d3-array/src/bisect.js` (safe): No malicious patterns detected; this is a standard D3.js array bisect utility module with only static imports and exports.
- `lib-vendor/d3-array/src/bisector.js` (safe): No malicious patterns detected; the file contains standard d3-array bisector logic with no network, filesystem, process, or dynamic execution concerns.
- `lib-vendor/d3-array/src/constant.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/count.js` (safe): No malicious patterns detected; the file is a simple count utility function with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-array/src/cross.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/cumsum.js` (safe): The code is a simple cumulative sum implementation using Float64Array with no malicious patterns detected.
- `lib-vendor/d3-array/src/descending.js` (safe): No malicious patterns found; this is a simple descending comparator function with no external calls or side effects.
- `lib-vendor/d3-array/src/deviation.js` (safe): No malicious patterns detected; the file contains a simple mathematical deviation calculation with no network, filesystem, process, or dynamic execution behavior.
- `lib-vendor/d3-array/src/difference.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/disjoint.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/every.js` (safe): No malicious patterns detected; the code is a simple array iteration utility with no network, filesystem, process, or dynamic code execution activity.
- `lib-vendor/d3-array/src/extent.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/filter.js` (safe): No malicious patterns detected; the code is a simple array filter utility with no network, filesystem, process, or dynamic execution behavior.
- `lib-vendor/d3-array/src/fsum.js` (safe): No malicious patterns detected; the code implements a floating-point sum algorithm with no network, file, process, or dynamic execution behavior.
- `lib-vendor/d3-array/src/greatest.js` (safe): The code is a standard implementation of a greatest/argmax utility function from the d3-array library with no malicious patterns detected.
- `lib-vendor/d3-array/src/greatestIndex.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/group.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/groupSort.js` (safe): No malicious patterns detected; the file contains standard d3-array groupSort implementation with Babel interop helpers, performing only local data grouping and sorting.
- `lib-vendor/d3-array/src/identity.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/index.js` (safe): This is a standard ES module re-export index file for the d3-array library, containing only static require() and Object.defineProperty() calls to expose known internal utilities with no dynamic or suspicious behavior.
- `lib-vendor/d3-array/src/intersection.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/least.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/leastIndex.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/map.js` (safe): No malicious patterns detected; the code is a simple iterable mapping utility with input validation and no side effects or external calls.
- `lib-vendor/d3-array/src/max.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/maxIndex.js` (safe): No malicious patterns detected; this is a standard d3-array maxIndex utility function with no network, filesystem, process, or dynamic code execution activity.
- `lib-vendor/d3-array/src/mean.js` (safe): No malicious patterns detected; the code is a standard statistical mean calculation function with no security concerns.
- `lib-vendor/d3-array/src/median.js` (safe): No malicious patterns detected; the code is a simple statistical median utility with no network, filesystem, or dynamic code execution behavior.
- `lib-vendor/d3-array/src/merge.js` (safe): No malicious patterns detected; the file contains a benign implementation of an array merge utility using a generator.
- `lib-vendor/d3-array/src/min.js` (safe): No malicious patterns detected; this is a benign min() utility function from d3-array.
- `lib-vendor/d3-array/src/minIndex.js` (safe): No malicious patterns detected; the code is a benign utility function mimicking d3-array's minIndex with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-array/src/mode.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/nice.js` (safe): No malicious patterns detected; the code is a standard d3-array utility for computing nice axis tick boundaries.
- `lib-vendor/d3-array/src/number.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/pairs.js` (safe): No malicious patterns detected; the code is a benign utility for creating pairs from an iterable.
- `lib-vendor/d3-array/src/permute.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/quantile.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/quickselect.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/range.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/rank.js` (safe): No malicious patterns detected; the code is a legitimate implementation of the rank function from d3-array.
- `lib-vendor/d3-array/src/reduce.js` (safe): The code implements a standard reduce function for iterables with no malicious patterns, external calls, or suspicious behavior.
- `lib-vendor/d3-array/src/reverse.js` (safe): The code is a benign utility function that reverses an iterable, with no malicious patterns detected.
- `lib-vendor/d3-array/src/scan.js` (safe): The code is a simple utility function for finding the index of the minimum value, with no malicious patterns, external calls, or unsafe operations.
- `lib-vendor/d3-array/src/shuffle.js` (safe): The code is a straightforward Fisher-Yates shuffle implementation with no malicious patterns, external calls, or suspicious behavior.
- `lib-vendor/d3-array/src/some.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/sort.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/subset.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/sum.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/superset.js` (safe): No malicious patterns detected; the code implements a benign superset-checking algorithm from d3-array.
- `lib-vendor/d3-array/src/threshold/freedmanDiaconis.js` (safe): No malicious patterns detected; the code is a simple statistical threshold calculation using D3 utility functions.
- `lib-vendor/d3-array/src/threshold/scott.js` (safe): No malicious patterns detected
- `lib-vendor/d3-array/src/threshold/sturges.js` (safe): The file implements a simple Sturges' formula threshold function using Math.log and a relative import of a local count utility, with no malicious patterns detected.
- `lib-vendor/d3-array/src/ticks.js` (safe): No malicious patterns detected; the code is a legitimate mathematical utility for computing tick values.
- `lib-vendor/d3-array/src/transpose.js` (safe): No malicious patterns detected; the file is a benign matrix transposition utility from d3-array.
- `lib-vendor/d3-array/src/union.js` (safe): No malicious patterns detected; the code is a simple utility function implementing a set union using InternSet with no external I/O, dynamic execution, or suspicious behavior.
- `lib-vendor/d3-array/src/variance.js` (safe): No malicious patterns detected; the file contains a standard statistical variance implementation with no network, filesystem, process, or dynamic execution activity.
- `lib-vendor/d3-array/src/zip.js` (safe): No malicious patterns detected; this is a benign utility module that re-exports the transpose function as zip.
- `lib-vendor/d3-color/src/color.js` (safe): No malicious patterns detected in the d3-color utility module.
- `lib-vendor/d3-color/src/cubehelix.js` (safe): No malicious patterns detected; this is a legitimate D3 color conversion module performing only mathematical color space transformations.
- `lib-vendor/d3-color/src/define.js` (safe): No malicious patterns detected; the file contains only standard prototype inheritance helper functions with no network, filesystem, process, or dynamic execution capabilities.
- `lib-vendor/d3-color/src/index.js` (safe): This is a standard Babel-compiled CommonJS entry point for the d3-color library that only re-exports functions from local sibling modules, with no network, filesystem, process, or dynamic code execution patterns.
- `lib-vendor/d3-color/src/lab.js` (safe): This file implements standard D3 color space conversion (Lab/HCL) with no malicious patterns, network activity, file system access, or dynamic code execution.
- `lib-vendor/d3-color/src/math.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/back.js` (safe): No malicious patterns detected; this is a standard, benign easing function implementation from the d3-ease library.
- `lib-vendor/d3-ease/src/bounce.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/circle.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/cubic.js` (safe): No malicious patterns detected; this is a standard implementation of cubic easing functions with no external I/O, environment access, dynamic execution, or network activity.
- `lib-vendor/d3-ease/src/elastic.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/exp.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/index.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/linear.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/math.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/poly.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/quad.js` (safe): No malicious patterns detected
- `lib-vendor/d3-ease/src/sin.js` (safe): No malicious patterns detected; the file contains only pure mathematical easing functions with no I/O, network, or dynamic code execution.
- `lib-vendor/d3-format/src/defaultLocale.js` (safe): This file is a benign locale configuration module from the d3-format library with no malicious patterns, network calls, obfuscation, or process execution.
- `lib-vendor/d3-format/src/exponent.js` (safe): No malicious patterns detected
- `lib-vendor/d3-format/src/formatDecimal.js` (safe): No malicious patterns detected
- `lib-vendor/d3-format/src/formatGroup.js` (safe): The code is a benign number formatting utility from the d3-format library with no malicious patterns detected.
- `lib-vendor/d3-format/src/formatNumerals.js` (safe): No malicious patterns detected
- `lib-vendor/d3-format/src/formatPrefixAuto.js` (safe): No malicious patterns detected; the code is a benign number formatting utility from the d3-format library.
- `lib-vendor/d3-format/src/formatRounded.js` (safe): No malicious patterns detected
- `lib-vendor/d3-format/src/formatSpecifier.js` (safe): No malicious patterns detected; the file only implements safe format specifier parsing for d3-format.
- `lib-vendor/d3-format/src/formatTrim.js` (safe): No malicious patterns detected; the file contains only a pure string-trimming utility with no I/O, network, or dynamic execution.
- `lib-vendor/d3-format/src/formatTypes.js` (safe): No malicious patterns detected
- `lib-vendor/d3-format/src/identity.js` (safe): No malicious patterns detected; the file contains a trivial identity function with no side effects, network activity, or dynamic execution.
- `lib-vendor/d3-format/src/index.js` (safe): No malicious patterns detected; the file is a standard Babel-compiled ES module index that only re-exports functions from local d3-format modules.
- `lib-vendor/d3-format/src/locale.js` (safe): This is a standard d3-format locale implementation with no malicious patterns detected.
- `lib-vendor/d3-format/src/precisionFixed.js` (safe): No malicious patterns detected
- `lib-vendor/d3-format/src/precisionPrefix.js` (safe): No malicious patterns detected
- `lib-vendor/d3-format/src/precisionRound.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/array.js` (safe): No malicious patterns detected; the code is a standard D3 array interpolation utility with only benign module imports and no data exfiltration, credential harvesting, dynamic execution, or process spawning.
- `lib-vendor/d3-interpolate/src/basis.js` (safe): This is a standard, non-obfuscated mathematical interpolation function from d3-interpolate with no network, filesystem, process, or dynamic code execution activity.
- `lib-vendor/d3-interpolate/src/basisClosed.js` (safe): No malicious patterns detected; the file is a legitimate mathematical interpolation utility from the d3-interpolate package with no network, filesystem, process, or dynamic execution activity.
- `lib-vendor/d3-interpolate/src/color.js` (safe): No malicious patterns detected; the file contains standard color interpolation logic from the d3-interpolate library with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-interpolate/src/constant.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/cubehelix.js` (safe): No malicious patterns detected; the file is a standard d3-interpolate cubehelix color interpolation module with no network, filesystem, process, or dynamic execution behavior.
- `lib-vendor/d3-interpolate/src/date.js` (safe): No malicious patterns detected; this is a legitimate d3-interpolate date interpolation function.
- `lib-vendor/d3-interpolate/src/discrete.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/hcl.js` (safe): No malicious patterns detected; this is a standard D3 color interpolation module with no network, file system, process execution, or obfuscated code.
- `lib-vendor/d3-interpolate/src/hsl.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/hue.js` (safe): No malicious patterns detected; this is a legitimate color hue interpolation utility from the d3-interpolate library.
- `lib-vendor/d3-interpolate/src/index.js` (safe): This is a standard Babel-compiled ES module index file for the d3-interpolate library that only re-exports interpolation functions with no malicious patterns.
- `lib-vendor/d3-interpolate/src/lab.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/number.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/numberArray.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/object.js` (safe): No malicious patterns detected; this is a standard d3-interpolate object interpolation utility with no network, filesystem, or dynamic execution activity.
- `lib-vendor/d3-interpolate/src/piecewise.js` (safe): No malicious patterns detected; this is a legitimate d3-interpolate utility for piecewise interpolation with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-interpolate/src/quantize.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/rgb.js` (safe): The code is a legitimate D3.js color interpolation module with no malicious patterns, network activity, or execution of untrusted input.
- `lib-vendor/d3-interpolate/src/round.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/string.js` (safe): No malicious patterns detected; this is a legitimate d3-interpolate string interpolation module.
- `lib-vendor/d3-interpolate/src/transform/decompose.js` (safe): No malicious patterns detected
- `lib-vendor/d3-interpolate/src/transform/index.js` (safe): No malicious patterns detected; this is a legitimate d3-interpolate transform interpolation module with only internal requires and pure math/string manipulation.
- `lib-vendor/d3-interpolate/src/transform/parse.js` (safe): No malicious patterns detected; this is a legitimate d3-interpolate transform parsing module with no exfiltration, code execution, or filesystem abuse.
- `lib-vendor/d3-interpolate/src/value.js` (safe): This is a standard d3-interpolate value selection module with no malicious patterns, network calls, file system access, or dynamic code execution.
- `lib-vendor/d3-interpolate/src/zoom.js` (safe): No malicious patterns detected; the code is a legitimate d3-interpolate zoom interpolation implementation using only pure math functions.
- `lib-vendor/d3-path/src/index.js` (safe): No malicious patterns detected
- `lib-vendor/d3-path/src/path.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/band.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/colors.js` (safe): No malicious patterns detected; the function only performs simple string parsing and formatting for color conversion.
- `lib-vendor/d3-scale/src/constant.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/continuous.js` (safe): No malicious patterns detected; the file contains standard D3 scale interpolation logic with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-scale/src/diverging.js` (safe): This is a legitimate vendored copy of d3-scale's diverging scale module with no malicious patterns, network calls, credential access, or dynamic code execution.
- `lib-vendor/d3-scale/src/identity.js` (safe): No malicious patterns detected; the code is a standard d3-scale identity scale implementation with no network, filesystem, process, or dynamic execution activity.
- `lib-vendor/d3-scale/src/index.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/init.js` (safe): No malicious patterns detected; the file contains only benign d3-scale initialization helper functions.
- `lib-vendor/d3-scale/src/linear.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/log.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/nice.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/number.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/ordinal.js` (safe): No malicious patterns detected; the code is a standard D3 ordinal scale implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `lib-vendor/d3-scale/src/pow.js` (safe): No malicious patterns detected; the file contains pure math/scale functions with no network, filesystem, process, or dynamic code execution.
- `lib-vendor/d3-scale/src/quantile.js` (safe): No malicious patterns detected; this is a legitimate d3-scale quantile scale implementation with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-scale/src/quantize.js` (safe): No malicious patterns detected; this is a standard D3 quantize scale implementation with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-scale/src/radial.js` (safe): No malicious patterns detected; this is a standard D3 scale implementation with no network, filesystem, process, or dynamic-code-execution behavior.
- `lib-vendor/d3-scale/src/sequential.js` (safe): No malicious patterns detected; this is a standard d3-scale sequential scale implementation with only mathematical/interpolation logic and local module imports.
- `lib-vendor/d3-scale/src/sequentialQuantile.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/symlog.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/threshold.js` (safe): No malicious patterns detected; this is a standard d3-scale threshold scale implementation with no network, filesystem, process, or dynamic code execution activity.
- `lib-vendor/d3-scale/src/tickFormat.js` (safe): No malicious patterns detected; the code is a standard d3-scale tick formatting utility with only internal module imports and no network, file, process, or dynamic execution behavior.
- `lib-vendor/d3-scale/src/time.js` (safe): No malicious patterns detected
- `lib-vendor/d3-scale/src/utcTime.js` (safe): No malicious patterns detected; this is a standard D3.js UTC time scale utility module with legitimate imports and no suspicious behavior.
- `lib-vendor/d3-shape/src/arc.js` (safe): This is a legitimate vendored copy of the d3-shape arc module containing only pure geometry/math code with no network, filesystem, process, or dynamic execution behavior.
- `lib-vendor/d3-shape/src/area.js` (safe): No malicious patterns detected; the file is a standard vendored d3-shape area generator with only relative imports and no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-shape/src/areaRadial.js` (safe): This is a standard D3.js areaRadial module with only local module imports and no malicious patterns.
- `lib-vendor/d3-shape/src/array.js` (safe): No malicious patterns detected; the file is a benign utility from the d3-shape library that normalizes array-like inputs.
- `lib-vendor/d3-shape/src/constant.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/curve/basis.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/curve/basisClosed.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/curve/basisOpen.js` (safe): No malicious patterns detected; this is a benign D3.js curve implementation with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-shape/src/curve/bump.js` (safe): No malicious patterns detected; the code is a legitimate D3 shape curve implementation with no network, filesystem, process, or dynamic execution activity.
- `lib-vendor/d3-shape/src/curve/bundle.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/curve/cardinal.js` (safe): No malicious patterns detected; the code is a standard D3 shape curve implementation with no network, filesystem, process, or dynamic code execution behavior.
- `lib-vendor/d3-shape/src/curve/cardinalClosed.js` (safe): No malicious patterns detected in this D3.js curve implementation; the code contains only benign geometric path calculations.
- `lib-vendor/d3-shape/src/curve/cardinalOpen.js` (safe): No malicious patterns detected; this is a benign d3-shape curve implementation with no network, filesystem, process, or dynamic execution behavior.
- `lib-vendor/d3-shape/src/curve/catmullRom.js` (safe): No malicious patterns detected; this is a legitimate D3.js shape curve implementation.
- `lib-vendor/d3-shape/src/curve/catmullRomClosed.js` (safe): No malicious patterns detected; the code is a legitimate implementation of the Catmull-Rom closed curve from the d3-shape library.
- `lib-vendor/d3-shape/src/curve/catmullRomOpen.js` (safe): This is a legitimate D3.js curve interpolation module with no malicious patterns, network activity, or code execution.
- `lib-vendor/d3-shape/src/curve/linear.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/curve/linearClosed.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/curve/monotone.js` (safe): No malicious patterns detected; the file is a legitimate D3 shape curve implementation with no network, file system, process, dynamic code, or credential access.
- `lib-vendor/d3-shape/src/curve/natural.js` (safe): No malicious patterns detected; this is a standard d3-shape natural cubic spline curve implementation.
- `lib-vendor/d3-shape/src/curve/radial.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/curve/step.js` (safe): No malicious patterns detected; the code is a legitimate d3-shape step curve implementation with no network, filesystem, process, or dynamic execution activity.
- `lib-vendor/d3-shape/src/descending.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/identity.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/index.js` (safe): No malicious patterns detected; this is a standard Babel-compiled ES module index file for the d3-shape library that only re-exports its own local modules.
- `lib-vendor/d3-shape/src/line.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/lineRadial.js` (safe): No malicious patterns detected; the code is a standard d3-shape module for radial line generation with only safe import/export and property manipulation logic.
- `lib-vendor/d3-shape/src/link.js` (safe): The code is a legitimate D3.js link shape generator module with no malicious patterns detected.
- `lib-vendor/d3-shape/src/math.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/noop.js` (safe): No malicious patterns detected
- `lib-vendor/d3-shape/src/offset/diverging.js` (safe): No malicious patterns detected; the code is a standard D3 shape offset implementation with no network, file system, process, or dynamic code execution activity.
- `lib-vendor/d3-shape/src/offset/expand.js` (safe): No malicious patterns detected; the code is a benign d3-shape stack offset implementation with only internal module imports and no dynamic execution, network, filesystem, or process activity.
- `lib-vendor/d3-shape/src/offset/none.js` (safe): No malicious patterns detected; the file contains a benign d3-shape offset implementation with no network, filesystem, process, or dynamic execution behavior.
- `lib-vendor/d3-shape/src/offset/silhouette.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
