What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-v6wh-96g9-6wx3 applies
Minor caution · medium confidence
A build tool used during development has a known security issue, but that tool is not part of the finished plugin that users install. The risk to end users is minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.
Contextual assessment: This advisory matches a dependency declared in the lockfile for a RisuAI browser plugin built with Vite. The project ships a single bundled JS file; build-time dev dependencies are not included in the runtime output. The production dependencies are limited to localforage, svelte, lucide-svelte, and a queue data structure, none of which are typical targets for this advisory class. The advisory most likely affects a dev-only tool such as Vite or PostCSS, whose vulnerable code paths involve development servers or build-time processing that do not execute when the built plugin runs inside RisuAI.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version during the next build cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6wh-96g9-6wx3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-phwv-c562-gvmh applies
Minor caution · medium confidence
A development-only tool has a known issue, but it does not affect the plugin that users actually run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-phwv-c562-gvmh to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory corresponds to a package in the lockfile of a Vite-built browser plugin. The shipped artifact is a single bundled JS file imported into RisuAI, and the four production runtime dependencies are simple client-side libraries with no known match for this advisory. The flagged package is most likely a dev dependency used only during the build process, meaning the vulnerable code is not present in the runtime environment where the plugin executes.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-phwv-c562-gvmh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rcqx-6q8c-2c42 applies
Minor caution · medium confidence
The flagged tool is used only during development and does not ship with the finished plugin, so users are not exposed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rcqx-6q8c-2c42 to a dependency declared by this repository.
Contextual assessment: This advisory matches a lockfile entry for a browser plugin that is compiled into a single JS bundle. The production dependency set is small and consists of client-side libraries unlikely to be the target. The advisory most plausibly affects a build-time dev dependency whose vulnerable code paths require a running development server or build-time input processing, neither of which occurs when the finished plugin operates inside RisuAI.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rcqx-6q8c-2c42
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4w7w-66w2-5vf9 applies
Minor caution · medium confidence
A development tool has a known flaw, but it is not included in the plugin users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory is matched against the lockfile of a Vite-compiled RisuAI plugin. The runtime ships as a single bundled file with four production dependencies that are simple client-side libraries. The advisory likely targets a dev-only package whose vulnerable behavior is confined to the build or development-server context and is absent from the deployed plugin.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4w7w-66w2-5vf9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-m56q-vw4c-c2cp applies
Minor caution · medium confidence
The security issue is in a build-time tool that is not part of the finished plugin, so end users are not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-m56q-vw4c-c2cp to a dependency declared by this repository.
Contextual assessment: This advisory is associated with a lockfile entry for a browser plugin built with Vite and Svelte. The production dependencies are limited to client-side libraries with no apparent match to this advisory. The flagged package is most likely a dev dependency used during the build process, and its vulnerable code paths do not execute in the bundled plugin output that runs inside RisuAI.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-m56q-vw4c-c2cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Minor caution · medium confidence
Although this issue is rated high severity, it affects a development tool that is not included in the plugin users install. The risk to end users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory is matched in the lockfile of a RisuAI browser plugin. Despite the higher scanner severity, the project ships only a single bundled JS file, and the production runtime dependencies are simple client-side libraries. The advisory most likely targets a dev dependency such as Vite or esbuild whose vulnerable code involves development server behavior that does not exist in the built plugin. No attacker-controlled input reaches the vulnerable code at runtime because the dev server is not part of the shipped artifact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
This high-severity issue is in a development tool that does not ship with the plugin. Users who install the finished plugin are not exposed to this risk.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: This high-severity advisory appears in the lockfile of a Vite-built browser plugin. The shipped output is a single bundled JS file with four production dependencies that are client-side libraries. The advisory most plausibly affects a dev dependency such as esbuild or Vite, where the vulnerable behavior requires a running development server accessible to attackers. That server is not present when the built plugin executes inside RisuAI, so the vulnerable code is not reachable at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version to secure the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-28wg-ghj8-5hjv applies
Minor caution · medium confidence
The flagged issue is in a development tool that is not part of the finished plugin, so users are not exposed to this risk.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-28wg-ghj8-5hjv to a dependency declared by this repository.
Contextual assessment: This high-severity advisory is matched against the lockfile of a RisuAI plugin compiled with Vite. The runtime artifact is a single bundled JS file, and the production dependencies are limited to simple client-side libraries. The advisory likely targets a dev dependency whose vulnerable code paths involve development server or build-time processing. Since the dev server and build tools are not part of the shipped plugin, the vulnerable code does not execute in the end-user environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-28wg-ghj8-5hjv
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5j98-mcp5-4vw2 applies
Minor caution · medium confidence
A tool used only during the building process has a known security issue. Since this tool is not included in the final plugin that users install, it does not directly affect people using the plugin. The developer should still update it to keep their build environment safe.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5j98-mcp5-4vw2 to a dependency declared by this repository.
Contextual assessment: This advisory likely corresponds to a transitive dependency of a build-time tool (such as tar, pulled in by npm/vite tooling). The project ships as a Vite-bundled browser plugin for RisuAI; dev and build dependencies are not included in the final dist JS artifact. The vulnerable code has no runtime reachability for end users of the plugin. The advisory still represents a weakness in the developer's build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build dependency to a patched version in your dev environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5j98-mcp5-4vw2
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qx2v-qp2m-jg93 applies
Minor caution · medium confidence
A building tool has a medium-level security issue. Because this tool is only used to create the plugin and is not part of the final product users install, it does not affect end users. Updating it is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory likely matches a build-tool dependency such as vite or postcss. These packages are listed as devDependencies and are used only during the Vite build process. The shipped artifact is a single bundled JS file for browser use within RisuAI, so the vulnerable code does not reach end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qx2v-qp2m-jg93
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · medium confidence
A building tool has a known security issue. Since it is not included in the final plugin, users are not affected. The developer should update it when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory likely corresponds to a build-time dependency. The project's production dependencies are limited to queue, localforage, lucide-svelte, and svelte, none of which are commonly associated with this advisory pattern. Build dependencies are not bundled into the shipped plugin artifact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
A high-severity issue was found in a tool used only during the build process. Because this tool is not part of the final plugin that users install, it does not affect end users. The developer should update it to protect their build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely matches a build-tool transitive dependency such as tar or a development server component. The project is a client-side browser plugin built with Vite; the final artifact is a bundled JS file that excludes dev dependencies. The vulnerable code has no runtime reachability in the shipped plugin.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A high-severity issue was found in a development tool. Since this tool is only used by the developer during building and is not included in the final plugin, users are not affected. The developer should update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely corresponds to a development server or build-tool dependency such as esbuild or vite. These are devDependencies used only during the build process and are not bundled into the shipped browser plugin artifact. End users of the plugin are not exposed to the vulnerable code at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A high-severity issue was found in a building tool. Because the tool is not part of the final plugin users install, it does not affect end users. The developer should update it to keep their environment secure.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely matches a build-tool dependency such as vite or a related transitive package. The project ships as a Vite-bundled browser plugin; dev dependencies are excluded from the final artifact. The vulnerable code does not reach end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2v37-7h3g-55p8 applies
Minor caution · medium confidence
A high-severity issue was found in a dependency. If it is in a building tool, it does not affect users. If it is in the UI framework, the specific type of attack it enables does not apply to this client-side plugin. The developer should still update the dependency.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2v37-7h3g-55p8 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory may correspond to svelte or a build-tool dependency. If it is a build-tool dependency, it does not ship in the final artifact. If it relates to svelte's SSR XSS advisory, the project is a client-side browser plugin without server-side rendering, so the SSR attack surface is not present. In either case, runtime reachability for end users is limited or absent.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version; if it is svelte, upgrade to a version that addresses the advisory.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2v37-7h3g-55p8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A high-severity issue was found in a development tool. Since this tool is not included in the final plugin that users install, it does not affect end users. The developer should update it to protect their build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely corresponds to a build-tool dependency such as vite, esbuild, or a transitive package. The project is a Vite-built browser plugin whose shipped artifact is a single bundled JS file that excludes dev dependencies. The vulnerable code has no runtime reachability for end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-pr6f-5x2q-rwfp applies
Minor caution · medium confidence
This flagged dependency is most likely a build tool that only runs on the developer's machine, not in the plugin that users install. The vulnerability would not affect people using the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-pr6f-5x2q-rwfp to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory most likely targets a build-time devDependency (e.g., Vite, PostCSS, or related tooling) declared in the lockfile. The project ships a single bundled browser-plugin JS file produced by Vite; devDependencies do not execute in the end-user runtime. Without attacker-controlled input reaching the vulnerable code during the build phase, and with no dev-server exposure for end users, runtime reachability to plugin consumers is negligible. The advisory affects the developer build environment at most.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-pr6f-5x2q-rwfp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fx2h-pf6j-xcff applies
Minor caution · medium confidence
Although the scanner rates this as high severity, the vulnerable tool is only used during development to build the plugin. It does not run when users install or use the plugin, so the risk to users is minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.
Contextual assessment: This high-severity advisory most likely corresponds to a Vite dev-server or build-tool vulnerability. Vite is declared as a devDependency (^5.0.0) and is used only to produce the bundled output. The shipped artifact is a static JS file imported into RisuAI; no Vite dev server or build pipeline runs in the end-user environment. The vulnerable code path requires a running dev server or build-time attacker input, neither of which is present for plugin consumers. Runtime reachability to end users is absent.
Impact: low · Exploitability: unlikely
Developer action: Upgrade Vite (and any related build tooling) to the latest patched version to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fx2h-pf6j-xcff
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-crpf-4hrx-3jrp applies
Minor caution · medium confidence
This flagged dependency is likely a development or build tool that does not get included in the plugin users install. The vulnerability would not affect plugin users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-crpf-4hrx-3jrp to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory most likely targets a build-time or type-definition dependency in the lockfile. The project's runtime dependencies are limited to localforage, svelte, lucide-svelte, and a queue data structure, none of which are common targets for this class of advisory. The build tooling dependencies (Vite, Terser, PostCSS, Tailwind, TypeScript types) do not ship in the bundled plugin output. Without runtime reachability to end users, the impact is confined to the developer build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-crpf-4hrx-3jrp
- File role
- production
- Source
- package-lock.json
Expected scanner matches (10)
Credential access and network transmission in one file
Expected behavior · high confidence
This code logs you into Google so the plugin can sync your data to Google Drive. It sends your login token only to Google's own website to get your profile information, which is the normal way Google login works. There is no sign of your credentials being sent anywhere suspicious.
Technical evidence
Scanner reason: A credential source and an outbound network operation were detected in the same file.
Contextual assessment: The flagged fetch call sends an OAuth2 access token as a Bearer header to the official Google userinfo endpoint. This is standard OAuth2 user profile retrieval for a plugin whose stated purpose includes Google Drive cloud sync and secure authentication. Tokens are stored and cleared through the host plugin API, and the only network destination shown is Google's own API domain. No evidence of transmission to third-party or attacker-controlled endpoints is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- tavernkeeper 3
- Rule
- credential-exfiltration
- File role
- production
- Source
- src/manager/auth.ts:203
Credential access and network transmission in one file
Expected behavior · high confidence
This plugin syncs data to Google Drive. To do that, it gets a Google login token and sends it to Google's own website to prove who you are. That is exactly how Google Drive sync is supposed to work. The token is not being sent anywhere suspicious.
Technical evidence
Scanner reason: A credential source and an outbound network operation were detected in the same file.
Contextual assessment: The file obtains an OAuth access token via AuthManager.getAccessToken() and transmits it as a standard Bearer Authorization header to the official Google Drive API endpoint at googleapis.com. This is the correct and expected pattern for authenticating Google Drive API requests. The project's stated purpose explicitly includes Google Drive cloud sync, and the token is sent only to Google's first-party API domain, not to any third-party or unexpected destination. No exfiltration, obfuscation, or off-purpose credential use is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- tavernkeeper 3
- Rule
- credential-exfiltration
- File role
- production
- Source
- src/manager/drive.ts:305
Dependency advisory GHSA-7r86-cg39-jmmj applies
Expected behavior · medium confidence
This is a security warning for a tool used only to build the plugin, not for the plugin itself. The finished plugin file that users load does not include this tool, so the warning does not affect people using the plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: The advisory targets a build-tooling dependency declared in this project. The shipped artifact is a single bundled JS file produced by Vite; the vulnerable package is consumed only during development/build and is not present in the runtime plugin loaded by RisuAI. The vulnerable code path (typically a dev-server or build-time input handling issue) has no runtime reachability for end users of the built plugin, and no attacker-controlled input reaches it during the hobbyist build pipeline.
Impact: none · Exploitability: unlikely
Developer action: Update the flagged build dependency to a patched version during routine maintenance; no urgent action is required for users of the built plugin.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-6g55-p6wh-862q applies
Expected behavior · medium confidence
The warning is about a program used to create the plugin, not the plugin that gets loaded. Because that helper program is not included in the final plugin, users are not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: This advisory concerns a development/build dependency. The project's runtime output is a bundled JS file imported into RisuAI; build-time packages such as bundlers, transpilers, or minifiers are not shipped to end users. The vulnerable code is not reachable at runtime, and the build pipeline for this hobbyist extension does not expose the vulnerable input path to an attacker.
Impact: none · Exploitability: unlikely
Developer action: Bump the affected dev dependency to a fixed version when convenient; no user-facing risk is present.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6g55-p6wh-862q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-67mh-4wv8-2f99 applies
Expected behavior · medium confidence
This warning points to a build-time helper tool. The final plugin file does not contain it, so people using the plugin are not exposed to this issue.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-67mh-4wv8-2f99 to a dependency declared by this repository.
Contextual assessment: The flagged dependency is part of the build toolchain. The vulnerable code is exercised only during development or local dev-server usage and is not included in the bundled dist artifact that RisuAI loads. There is no runtime reachability and no attacker-controlled input path reaching the vulnerable function in this extension's build context.
Impact: none · Exploitability: unlikely
Developer action: Update the dev dependency to a patched release during normal maintenance; no urgent fix is needed for plugin users.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-67mh-4wv8-2f99
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Expected behavior · medium confidence
The flagged tool is only used to build the plugin and is not part of the plugin that users load, so this warning does not affect plugin users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: This advisory applies to a build/development dependency. The extension ships as a single bundled JS file; the vulnerable package is consumed only at build time and is not present in the runtime artifact. The vulnerable code path is not reachable by end users, and the build inputs for this hobbyist project are not attacker-controlled.
Impact: none · Exploitability: unlikely
Developer action: Upgrade the affected build dependency to a fixed version when convenient; no immediate user-facing action is required.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f7gr-6p89-r883 applies
Expected behavior · medium confidence
This is a warning for a tool used during development only. The finished plugin does not include that tool, so users are not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f7gr-6p89-r883 to a dependency declared by this repository.
Contextual assessment: The advisory targets a development/build dependency. The runtime plugin is a bundled JS file that does not include build tooling packages. The vulnerable code has no runtime reachability in the shipped artifact, and the build-time input required to trigger it is not exposed to attackers in this project's workflow.
Impact: none · Exploitability: unlikely
Developer action: Update the dev dependency to a patched version as part of routine upkeep; no urgent user action is needed.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f7gr-6p89-r883
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Expected behavior · medium confidence
The warning is about a build helper, not the plugin itself. Since the helper is not included in the final plugin, users are not exposed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: This advisory concerns a build-time dependency. The vulnerable package is used only during development or bundling and is not part of the runtime JS file loaded by RisuAI. There is no runtime reachability and no attacker-controlled input reaching the vulnerable code in this extension's build pipeline.
Impact: none · Exploitability: unlikely
Developer action: Bump the affected build dependency to a fixed release during normal maintenance; no user-facing risk is present.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mw96-cpmx-2vgc applies
Expected behavior · medium confidence
This warning points to a tool used to build the plugin. The final plugin file does not contain it, so users are not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.
Contextual assessment: The flagged dependency is part of the development/build toolchain. The shipped plugin is a single bundled JS file; build tooling is not included in the runtime artifact loaded by RisuAI. The vulnerable code path is not reachable at runtime, and the build inputs are not attacker-controlled in this hobbyist project.
Impact: none · Exploitability: unlikely
Developer action: Upgrade the affected dev dependency to a patched version when convenient; no urgent fix is needed for plugin users.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mw96-cpmx-2vgc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Expected behavior · medium confidence
The flagged tool is only used to build the plugin and is not part of the plugin users load, so this warning does not affect plugin users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: This advisory applies to a build/development dependency. The extension's runtime output is a bundled JS file that does not ship build tooling packages. The vulnerable code is not reachable at runtime, and the build-time input required to trigger the issue is not exposed to attackers in this project's workflow.
Impact: none · Exploitability: unlikely
Developer action: Update the dev dependency to a patched version as part of routine upkeep; no immediate user action is required.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json