npm
zod
1 versiondiscovered · its AI-security audit & verification record by name.
3.24.1auditedresolved-commitverified
coverage →colinhacks/zod @ 0718293a4b5c6d7e…
AI security assessmentfindingsrisk: lowqwen2.5-7b-instruct
A validation regex with nested quantifiers may backtrack catastrophically.
- lowPotentially catastrophic backtracking in string-format regexCWE-1333src/types.ts:611
Methodology
Sources @ 0718293a4b
README.md, src/types.ts, src/ZodError.ts, src/helpers/parseUtil.ts, src/helpers/util.ts
Parts 5 files, 10900 bytes
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local
classes examined: CWE-1333
Gate this package in CI
Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.
signet gate --purl pkg:npm/zod@3.24.1 --registry https://signet.seekerslab.com
README badge
Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.
