TavernKeeper Scan Report

Coneja-Chibi/VectHare

Commit 3339e64 Reviewed

No material or high-risk concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 high 0 material 24 low

What this review found

No material or high-risk item was identified.

Minor cautions

Dependency advisory GHSA-5xrq-8626-4rwp applies

Minor caution · high confidence

A tool used for testing the software has a known security flaw. Since it's only used for testing and not in the actual extension, it poses a low risk to users but should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.

Contextual assessment: The OSV-Scanner matched a known critical advisory against a declared dependency in the test lockfile. The root project is 'vecthare-tests' and its dependencies are devDependencies used for testing. These vulnerabilities do not affect the shipped extension runtime but could affect the development or CI environment if tests are run in a compromised context.

Impact: low · Exploitability: plausible

Developer action: Update the vulnerable devDependencies in package.json and regenerate package-lock.json to resolve the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5xrq-8626-4rwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v6wh-96g9-6wx3 applies

Minor caution · high confidence

A tool used for testing the software has a known security flaw. Since it's only used for testing and not in the actual extension, it poses a low risk to users but should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.

Contextual assessment: The OSV-Scanner matched a known medium advisory against a declared dependency in the test lockfile. The root project is 'vecthare-tests' and its dependencies are devDependencies used for testing. These vulnerabilities do not affect the shipped extension runtime but could affect the development or CI environment if tests are run in a compromised context.

Impact: low · Exploitability: plausible

Developer action: Update the vulnerable devDependencies in package.json and regenerate package-lock.json to resolve the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6wh-96g9-6wx3
File role
production
Source
package-lock.json

Dependency advisory GHSA-25h7-pfq9-p65f applies

Minor caution · high confidence

A tool used for testing the software has a known security flaw. Since it's only used for testing and not in the actual extension, it poses a low risk to users but should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-25h7-pfq9-p65f to a dependency declared by this repository.

Contextual assessment: The OSV-Scanner matched a known high advisory against a declared dependency in the test lockfile. The root project is 'vecthare-tests' and its dependencies are devDependencies used for testing. These vulnerabilities do not affect the shipped extension runtime but could affect the development or CI environment if tests are run in a compromised context.

Impact: low · Exploitability: plausible

Developer action: Update the vulnerable devDependencies in package.json and regenerate package-lock.json to resolve the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-25h7-pfq9-p65f
File role
production
Source
package-lock.json

Dependency advisory GHSA-4w7w-66w2-5vf9 applies

Minor caution · high confidence

A tool used for testing the software has a known security flaw. Since it's only used for testing and not in the actual extension, it poses a low risk to users but should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.

Contextual assessment: The OSV-Scanner matched a known medium advisory against a declared dependency in the test lockfile. The root project is 'vecthare-tests' and its dependencies are devDependencies used for testing. These vulnerabilities do not affect the shipped extension runtime but could affect the development or CI environment if tests are run in a compromised context.

Impact: low · Exploitability: plausible

Developer action: Update the vulnerable devDependencies in package.json and regenerate package-lock.json to resolve the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4w7w-66w2-5vf9
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Minor caution · high confidence

A tool used for testing the software has a known security flaw. Since it's only used for testing and not in the actual extension, it poses a low risk to users but should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: The OSV-Scanner matched a known high advisory against a declared dependency in the test lockfile. The root project is 'vecthare-tests' and its dependencies are devDependencies used for testing. These vulnerabilities do not affect the shipped extension runtime but could affect the development or CI environment if tests are run in a compromised context.

Impact: low · Exploitability: plausible

Developer action: Update the vulnerable devDependencies in package.json and regenerate package-lock.json to resolve the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · high confidence

A tool used for testing the software has a known security flaw. Since it's only used for testing and not in the actual extension, it poses a low risk to users but should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: The OSV-Scanner matched a known high advisory against a declared dependency in the test lockfile. The root project is 'vecthare-tests' and its dependencies are devDependencies used for testing. These vulnerabilities do not affect the shipped extension runtime but could affect the development or CI environment if tests are run in a compromised context.

Impact: low · Exploitability: plausible

Developer action: Update the vulnerable devDependencies in package.json and regenerate package-lock.json to resolve the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Minor caution · high confidence

A tool used for testing the software has a known security flaw. Since it's only used for testing and not in the actual extension, it poses a low risk to users but should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: The OSV-Scanner matched a known high advisory against a declared dependency in the test lockfile. The root project is 'vecthare-tests' and its dependencies are devDependencies used for testing. These vulnerabilities do not affect the shipped extension runtime but could affect the development or CI environment if tests are run in a compromised context.

Impact: low · Exploitability: plausible

Developer action: Update the vulnerable devDependencies in package.json and regenerate package-lock.json to resolve the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-6g55-p6wh-862q applies

Minor caution · high confidence

A tool used for testing the software has a known security flaw. Since it's only used for testing and not in the actual extension, it poses a low risk to users but should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.

Contextual assessment: The OSV-Scanner matched a known high advisory against a declared dependency in the test lockfile. The root project is 'vecthare-tests' and its dependencies are devDependencies used for testing. These vulnerabilities do not affect the shipped extension runtime but could affect the development or CI environment if tests are run in a compromised context.

Impact: low · Exploitability: plausible

Developer action: Update the vulnerable devDependencies in package.json and regenerate package-lock.json to resolve the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6g55-p6wh-862q
File role
production
Source
package-lock.json

Dependency advisory GHSA-67mh-4wv8-2f99 applies

Minor caution · high confidence

This is a known security issue in a tool used for testing the extension, not in the extension itself. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-67mh-4wv8-2f99 to a dependency declared by this repository.

Contextual assessment: The lockfile is for the 'vecthare-tests' package and declares only devDependencies (vitest, jsdom). This vulnerability affects a development or testing dependency, not the runtime extension code loaded by SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependency to a patched version if convenient, but no urgent action is required for extension safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-67mh-4wv8-2f99
File role
production
Source
package-lock.json

Dependency advisory GHSA-rf6f-7fwh-wjgh applies

Minor caution · high confidence

This is a known security issue in a tool used for testing the extension, not in the extension itself. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.

Contextual assessment: The lockfile is for the 'vecthare-tests' package and declares only devDependencies (vitest, jsdom). This vulnerability affects a development or testing dependency, not the runtime extension code loaded by SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependency to a patched version if convenient, but no urgent action is required for extension safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rf6f-7fwh-wjgh
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · high confidence

This is a known security issue in a tool used for testing the extension, not in the extension itself. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: The lockfile is for the 'vecthare-tests' package and declares only devDependencies (vitest, jsdom). This vulnerability affects a development or testing dependency, not the runtime extension code loaded by SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependency to a patched version if convenient, but no urgent action is required for extension safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · high confidence

This is a known security issue in a tool used for testing the extension, not in the extension itself. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: The lockfile is for the 'vecthare-tests' package and declares only devDependencies (vitest, jsdom). This vulnerability affects a development or testing dependency, not the runtime extension code loaded by SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependency to a patched version if convenient, but no urgent action is required for extension safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-mw96-cpmx-2vgc applies

Minor caution · high confidence

This is a known security issue in a tool used for testing the extension, not in the extension itself. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.

Contextual assessment: The lockfile is for the 'vecthare-tests' package and declares only devDependencies (vitest, jsdom). This vulnerability affects a development or testing dependency, not the runtime extension code loaded by SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependency to a patched version if convenient, but no urgent action is required for extension safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mw96-cpmx-2vgc
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · high confidence

This is a known security issue in a tool used for testing the extension, not in the extension itself. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: The lockfile is for the 'vecthare-tests' package and declares only devDependencies (vitest, jsdom). This vulnerability affects a development or testing dependency, not the runtime extension code loaded by SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependency to a patched version if convenient, but no urgent action is required for extension safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-qx2v-qp2m-jg93 applies

Minor caution · high confidence

This is a known security issue in a tool used for testing the extension, not in the extension itself. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.

Contextual assessment: The lockfile is for the 'vecthare-tests' package and declares only devDependencies (vitest, jsdom). This vulnerability affects a development or testing dependency, not the runtime extension code loaded by SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependency to a patched version if convenient, but no urgent action is required for extension safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qx2v-qp2m-jg93
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · high confidence

This is a known security issue in a tool used for testing the extension, not in the extension itself. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: The lockfile is for the 'vecthare-tests' package and declares only devDependencies (vitest, jsdom). This vulnerability affects a development or testing dependency, not the runtime extension code loaded by SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependency to a patched version if convenient, but no urgent action is required for extension safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-96hv-2xvq-fx4p applies

Minor caution · medium confidence

A known security issue was found in a package used only for running tests, not in the actual extension that users install. This is a minor issue because the vulnerable code is not part of what users run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-96hv-2xvq-fx4p to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-96hv-2xvq-fx4p against a dependency declared in the vecthare-tests lockfile. The root package declares only devDependencies (vitest, jsdom, and related tooling), so this vulnerability resides in a development-time transitive dependency and does not ship with the extension runtime. No evidence of malicious code or credential handling was found in the supplied lockfile context.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient. Run npm audit fix or bump the relevant testing tool to its latest release.

Scanner
osv-scanner 2.4.0
Rule
GHSA-96hv-2xvq-fx4p
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Minor caution · medium confidence

A known security issue was found in a testing-only package. Since this code is not part of the extension users install, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 against a dependency in the vecthare-tests lockfile. The lockfile root contains only devDependencies for testing infrastructure, indicating this is a development-time transitive dependency vulnerability with no runtime exposure to extension users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A known security issue was found in a testing-only package. This does not affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg against a dependency in the vecthare-tests lockfile. The root package declares only devDependencies, so this vulnerability is confined to the development toolchain and does not affect the extension runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-58qx-3vcg-4xpx applies

Minor caution · medium confidence

A known security issue was found in a testing-only package. This does not affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-58qx-3vcg-4xpx to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-58qx-3vcg-4xpx (medium severity) against a dependency in the vecthare-tests lockfile. The lockfile root contains only devDependencies, confining this vulnerability to the development environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-58qx-3vcg-4xpx
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Minor caution · medium confidence

A known security issue was found in a testing-only package. This does not affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj against a dependency in the vecthare-tests lockfile. The root package declares only devDependencies, so this is a development-time transitive dependency vulnerability with no runtime exposure.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A known security issue was found in a testing-only package. This does not affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 against a dependency in the vecthare-tests lockfile. The lockfile root contains only devDependencies for testing infrastructure, confining this vulnerability to the development environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json

Dependency advisory GHSA-fx2h-pf6j-xcff applies

Minor caution · medium confidence

A known security issue was found in a testing-only package. This does not affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff against a dependency in the vecthare-tests lockfile. The root package declares only devDependencies, so this vulnerability is confined to the development toolchain and does not affect the extension runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fx2h-pf6j-xcff
File role
production
Source
package-lock.json
Expected scanner matches (0)

None.

Related contextual observations

All vulnerability findings are in a test-only lockfile with devDependencies

low risk · medium confidence

All seven security warnings are in packages used only for running tests, not in the actual extension. The testing tools have some known issues in their sub-dependencies, but these do not affect users who install the extension.

Technical assessment

The supplied lockfile is named vecthare-tests and its root package declares only devDependencies: vitest, vitest coverage and UI packages, and jsdom. All seven OSV-Scanner findings are known-advisory matches against transitive dependencies of these testing tools. No production runtime dependencies are declared in this lockfile, and no malicious code, credential exfiltration, or suspicious network destinations were observed in the supplied context. The file_role is labeled production, but the package name and contents indicate this is a development testing lockfile.

Impact: low · Exploitability: unlikely

Developer action: Periodically run npm audit and update testing dependencies to their latest patched versions. Consider separating test and production lockfiles if not already done, and ensure the production extension package does not inadvertently include devDependencies.

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity