java-topology/defects/openai-node/CLEAN.md
russell@unturf.com 0dbb699821 openai SDK dependency chain CWE-407 scan: all 5 targets CLEAN
openai-python, httpx, pydantic, tiktoken, openai-node — no CWE-407 defects.
All targets use proper dict/set/frozenset for membership tests in hot paths.
2026-03-30 16:44:33 -04:00

1.2 KiB

openai-node: CLEAN

CWE-407 scan: 2026-03-30

Source: https://github.com/openai/openai-node (depth=1)

Scan scope

  • src/ — 225 TypeScript files
  • Focus: streaming assembly, tool dedup, retry logic, .includes(), .indexOf(), .find()
  • Keywords: .includes(, .indexOf(, .find( in loops

Findings

No CWE-407 defects found.

  • lib/ChatCompletionStream.ts:306tools?.find() is O(T) but called once per tool call completion (not per chunk), and T is bounded (typically < 10)
  • lib/parser.ts:239,263 — same pattern, tool lookup by name, bounded
  • lib/transform.ts:79required.includes(key) inside properties loop is O(P*R), but called once during schema preparation with small JSON schemas
  • internal/qs/utils.ts:228refs.indexOf(val) in BFS graph walk is O(N^2), but this compact() function is dead code (exported but never imported by any module)
  • _vendor/zod-to-json-schema/parsers/union.ts:47,78,83.includes() in reduce but operating on Zod primitive types (bounded to ~7 types)

Verdict

CLEAN — proper data structure choices throughout. The only O(N^2) pattern is in dead vendored code (qs compact function, never called).