TavernKeeper Scan Report
Mnehmos/mnehmos.quest-keeper.game
Commit 84a067d Reviewed
No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger 0 material 101 low
What this review found
No material or immediate-danger item was identified.
Deterministic technical evidence (101)
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:13
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/release.yml:18
-
Dependency advisory RUSTSEC-2025-0080:pkg:d9db6230dfa23e8ba0fa93cf applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:d0433ccd51b55fc561da06bf applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-v2wj-q39q-566r:pkg:2da03775dcf45324bfa61d36 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2024-0414:pkg:e12ed7daa8c1d8360f101be8 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:c56121eae41b737e771f5dfe applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
zizmor reported excessive-permissions · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
JavaScript analysis reported javascript.xray.obfuscated-code · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-tooling· Execution scope: tooling-onlySource: scripts/checkpoint-database.js:1
-
OpenGrep reported tavernkeeper.dynamic-execution.node-shell · opengrep 1.26.0
This technical signal is not part of the shipped runtime behavior.
Policy reason:
owned-inert-tooling· Execution scope: tooling-onlySource: scripts/dev-server.js:135-140
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:16
-
Dependency advisory GHSA-cq8v-f236-94qc:pkg:3025fc3ef3bf079927f963fc applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-tooling· Execution scope: tooling-onlySource: scripts/dev-server.js:63
-
Dependency advisory GHSA-23c5-xmqv-rm74:pkg:732c7481baa8e54386dfde00 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/release.yml:27
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
Dependency advisory GHSA-5xrq-8626-4rwp:pkg:9050b80cbfdd759d03b3d57f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2026-0097:pkg:67ad090387f960532cd231b9 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-3v7f-55p6-f55p:pkg:6567e5dee65459862e18aa65 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2024-0411:pkg:7048d8a9d3d0f0ec2dd07bfe applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
OpenGrep reported tavernkeeper.dynamic-execution.node-shell · opengrep 1.26.0
This technical signal is not part of the shipped runtime behavior.
Policy reason:
owned-inert-tooling· Execution scope: tooling-onlySource: scripts/dev-server.js:123-128
-
Dependency advisory GHSA-cq8v-f236-94qc:pkg:7c09c7b6ff1c344041f9bc7a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0370:pkg:9b268f40461da81c7a1c55ed applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-7r86-cg39-jmmj:pkg:1a39cca405ef708861dee501 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2024-0413:pkg:c2f358c9f3bc98a14e0c2abf applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-25h7-pfq9-p65f:pkg:b1d04aa3fb09699f2ce52d11 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-wrw7-89jp-8q8g:pkg:4b30aae73f1836d87a5b008c applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/release.yml:21
-
Dependency advisory GHSA-mh99-v99m-4gvg:pkg:a3638530d49c16954a754a83 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-r6v5-fh4h-64xc:pkg:8c88822499350af2ff5f33b3 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:39
-
Dependency advisory RUSTSEC-2026-0221:pkg:44eb386acc1a4f9a94166f13 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-w5hq-g745-h8pq:pkg:dc7b41cc886ce4ad03b2d732 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2025-0081:pkg:5c764120c78ffcfe5027b39c applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-r28c-9q8g-f849:pkg:309438d8c981844c76003c01 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-96hv-2xvq-fx4p:pkg:e7e644a7c4ee2328aaaf410f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:ac373679d1ec0446c126c2b6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-f886-m6hf-6m8v:pkg:16af9086b5e4ae9e3d4dc665 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:dd82781926efc7ade22030d3 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/release.yml:21
-
Dependency advisory GHSA-rf6f-7fwh-wjgh:pkg:b63e05e77a564d495c499726 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
Dependency advisory RUSTSEC-2024-0429:pkg:d2e88fc02f6be9987f66e6e8 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
OpenGrep reported tavernkeeper.dynamic-execution.node-shell · opengrep 1.26.0
This technical signal is not part of the shipped runtime behavior.
Policy reason:
owned-inert-tooling· Execution scope: tooling-onlySource: scripts/dev-server.js:91
-
Dependency advisory GHSA-4w7w-66w2-5vf9:pkg:b05cf1d2fd08e11489a53642 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:13
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
Dependency advisory GHSA-4x5r-pxfx-6jf8:pkg:7fa3c5a48e754ae0b1b6d3d5 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2026-0195:pkg:b2765c7b11c24ec2d7e87302 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-tooling· Execution scope: tooling-onlySource: vite.config.ts:5
-
Dependency advisory GHSA-6g55-p6wh-862q:pkg:be20184562ed7ac60b9bb3c5 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
OpenGrep reported tavernkeeper.dynamic-execution.node-shell · opengrep 1.26.0
This technical signal is not part of the shipped runtime behavior.
Policy reason:
owned-inert-tooling· Execution scope: tooling-onlySource: scripts/dev-server.js:76
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/release.yml:55
-
Dependency advisory GHSA-48c2-rrv3-qjmp:pkg:4a13c1a979a3f31a165653c6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2026-0007:pkg:9ccfb94ee491ab6ac686a617 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:19b149914c26cb2c9c5de439 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:006e2a19c763cc0fc17b9679 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:80dc2988b9d15a40674cea67 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2025-0100:pkg:bd8adf60c37242745cb633a0 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0418:pkg:b245323ca01b322dae07bf9b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0420:pkg:d1377594ef97b5997d1bd6e4 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-7gcf-g7xr-8hxj:pkg:9b3ae1ede32e40256c2ca834 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0415:pkg:7feb02dbce543e0572f8f169 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2025-0075:pkg:3e15a087e2f1d00bbc8d944a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2025-0098:pkg:bc6e2fc910a7ca702c31e56a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-tooling· Execution scope: tooling-onlySource: scripts/dev-server.js:39
-
Dependency advisory GHSA-67mh-4wv8-2f99:pkg:9f437f50cb9a95220530f4b0 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-2v37-7h3g-55p8:pkg:a9b17cadf83e3a5de547592b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
zizmor reported excessive-permissions · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:10-25
-
Dependency advisory RUSTSEC-2024-0416:pkg:c8c328b18837aef0f997eeec applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2026-0097:pkg:2de12843da62fa20376b0d24 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-p9ff-h696-f583:pkg:4fdb809d17c4d326174c35f0 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-434x-w66g-qw3r:pkg:c9f3d96cd2462e5785d562d1 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-c2c7-rcm5-vvqj:pkg:6159a1838ee53aace6ac3052 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:0546a3b9043a41cf17d6475f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2026-0190:pkg:d7ee54a94ea24d860c852143 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-mw96-cpmx-2vgc:pkg:c29ae50f5c015b1c7e6647c6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
zizmor reported excessive-permissions · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:1-60
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:30
-
Dependency advisory GHSA-c2c7-rcm5-vvqj:pkg:09f761f2e2a83fdc7890eb5a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2024-0419:pkg:694df782baf029578982f056 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-3ppc-4f35-3m26:pkg:5b0d86b7147a191050fb118c applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2024-0412:pkg:4216c3e2f95d873b67813c23 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:33
-
zizmor reported excessive-permissions · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:27-60
-
Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:4d43116c7f40e099d5763941 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-3v7f-55p6-f55p:pkg:972939a004a2a625fbda61c7 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2026-0009:pkg:d5d0113eb9ce1f0b88860edc applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-7gmj-67g7-phm9:pkg:159f7c63ad1aed7f2fafff4f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
Dependency advisory RUSTSEC-2025-0057:pkg:1633dc8b81d03c690f20f67d applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2026-0194:pkg:c76651dee8ca612c7ddff8a9 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-hmw2-7cc7-3qxx:pkg:b7ecfe36ec4fd3c96631003d applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory GHSA-58qx-3vcg-4xpx:pkg:ba90529056af7ce6d840dc82 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/ci.yml:30
-
Dependency advisory GHSA-4w7w-66w2-5vf9:pkg:cdcea1ddcbe6ed9555aaec70 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
OpenGrep reported tavernkeeper.dynamic-execution.node-shell · opengrep 1.26.0
This technical signal is not part of the shipped runtime behavior.
Policy reason:
owned-inert-tooling· Execution scope: tooling-onlySource: scripts/dev-server.js:63
-
Dependency advisory RUSTSEC-2024-0417:pkg:38b1a8e2b331be3a60dc921d applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
Coverage and limitations
JavaScript coverage
Unresolved JavaScript stages
src/components/ThemeSelector.tsx— raw-ast / parsesrc/components/adventure/AdventureView.tsx— raw-ast / parsesrc/components/adventure/CharacterCreationModal.tsx— raw-ast / parsesrc/components/character/ConcentrationIndicator.tsx— raw-ast / parsesrc/components/character/ConditionsDisplay.tsx— raw-ast / parsesrc/components/character/CustomEffectsDisplay.tsx— raw-ast / parsesrc/components/character/LevelUpModal.tsx— raw-ast / parsesrc/components/character/SpellBookView.tsx— raw-ast / parsesrc/components/character/SpellSlotsDisplay.tsx— raw-ast / parsesrc/components/chat/CensorBlock.tsx— raw-ast / parsesrc/components/chat/Spoiler.tsx— raw-ast / parsesrc/components/chat/StreamingMessage.tsx— raw-ast / parsesrc/components/chat/ToolCallDisplay.tsx— raw-ast / parsesrc/components/common/ConditionBadge.tsx— raw-ast / parsesrc/components/common/ConfirmModal.tsx— raw-ast / parsesrc/components/common/SelectionStatusIndicator.tsx— raw-ast / parsesrc/components/common/XPBar.tsx— raw-ast / parsesrc/components/hud/AuraListPanel.tsx— raw-ast / parsesrc/components/hud/CharacterQuickView.tsx— raw-ast / parsesrc/components/hud/CombatHUD.test.tsx— raw-ast / parsesrc/components/hud/CombatHUD.tsx— raw-ast / parsesrc/components/hud/LootPanel.tsx— raw-ast / parsesrc/components/hud/PartyStatusBar.tsx— raw-ast / parsesrc/components/hud/QuickActionBar.tsx— raw-ast / parsesrc/components/hud/RestPanel.tsx— raw-ast / parsesrc/components/hud/SpellbookDrawer.tsx— raw-ast / parsesrc/components/hud/TurnOrderBar.tsx— raw-ast / parsesrc/components/layout/AppLayout.tsx— raw-ast / parsesrc/components/layout/MainViewport.tsx— raw-ast / parsesrc/components/layout/NavBar.tsx— raw-ast / parsesrc/components/layout/TerminalPanel.tsx— raw-ast / parsesrc/components/npc/NpcMemoryTimeline.tsx— raw-ast / parsesrc/components/npc/NpcRelationshipCard.tsx— raw-ast / parsesrc/components/party/CharacterCreationModal.tsx— raw-ast / parsesrc/components/party/CharacterPickerModal.tsx— raw-ast / parsesrc/components/party/PartyCreatorModal.tsx— raw-ast / parsesrc/components/party/PartyPanel.tsx— raw-ast / parsesrc/components/party/PartySelector.tsx— raw-ast / parsesrc/components/session/CampaignSetupWizard.tsx— raw-ast / parsesrc/components/session/WorldGenerationModal.tsx— raw-ast / parsesrc/components/settings/SettingsModal.tsx— raw-ast / parsesrc/components/terminal/ChatHistory.tsx— raw-ast / parsesrc/components/terminal/ChatInput.tsx— raw-ast / parsesrc/components/terminal/ChatSidebar.tsx— raw-ast / parsesrc/components/viewport/AuraLayer.tsx— raw-ast / parsesrc/components/viewport/AuraRing.tsx— raw-ast / parsesrc/components/viewport/BattlemapCanvas.tsx— raw-ast / parsesrc/components/viewport/CameraControls.tsx— raw-ast / parsesrc/components/viewport/CharacterEditModal.tsx— raw-ast / parsesrc/components/viewport/CharacterHeader.tsx— raw-ast / parsesrc/components/viewport/CharacterSheetView.tsx— raw-ast / parsesrc/components/viewport/EntityLayer.tsx— raw-ast / parsesrc/components/viewport/EntityTooltip.tsx— raw-ast / parsesrc/components/viewport/GridSystem.tsx— raw-ast / parsesrc/components/viewport/InventoryView.tsx— raw-ast / parsesrc/components/viewport/LineOfSight.tsx— raw-ast / parsesrc/components/viewport/NotesView.tsx— raw-ast / parsesrc/components/viewport/NpcJournalView.tsx— raw-ast / parsesrc/components/viewport/POIDetailPanel.tsx— raw-ast / parsesrc/components/viewport/SettingsView.tsx— raw-ast / parsesrc/components/viewport/Terrain.tsx— raw-ast / parsesrc/components/viewport/TerrainTooltip.tsx— raw-ast / parsesrc/components/viewport/Token.tsx— raw-ast / parsesrc/components/viewport/VisualizationControls.tsx— raw-ast / parsesrc/components/viewport/WorldEnvironmentForm.tsx— raw-ast / parsesrc/components/viewport/WorldEnvironmentOverlay.tsx— raw-ast / parsesrc/components/viewport/WorldMapCanvas.tsx— raw-ast / parsesrc/components/viewport/WorldStateView.tsx— raw-ast / parsesrc/components/viewport/models/ConnectedWater.tsx— raw-ast / parsesrc/components/viewport/models/CreatureLibrary.tsx— raw-ast / parsesrc/components/viewport/models/ProceduralCreature.tsx— raw-ast / parsesrc/components/viewport/models/ProceduralProps.tsx— raw-ast / parsesrc/components/viewport/models/index.ts— raw-ast / parsesrc/components/viewport/models/modelRegistry.ts— raw-ast / parsesrc/components/visualizers/NationCard.tsx— raw-ast / parsesrc/components/visualizers/RegionCard.tsx— raw-ast / parsesrc/components/visualizers/WorldStateCard.tsx— raw-ast / parsesrc/components/visualizers/WorldVisualization.tsx— raw-ast / parsesrc/context/ThemeContext.tsx— raw-ast / parsesrc/data/dnd5eItems.ts— raw-ast / parsesrc/data/playerGuide.ts— raw-ast / parsesrc/data/startingGear.ts— raw-ast / parsesrc/data/tips.ts— raw-ast / parsesrc/data/xpTable.ts— raw-ast / parsesrc/hooks/useAutoScroll.ts— raw-ast / parsesrc/hooks/useStreamingText.ts— raw-ast / parsesrc/main.tsx— raw-ast / parsesrc/services/eventPoller.ts— raw-ast / parsesrc/services/llm/LLMService.ts— raw-ast / parsesrc/services/llm/contextBuilder.ts— raw-ast / parsesrc/services/llm/providers/AnthropicProvider.ts— raw-ast / parsesrc/services/llm/providers/GeminiProvider.ts— raw-ast / parsesrc/services/llm/providers/OpenAIProvider.ts— raw-ast / parsesrc/services/llm/types.ts— raw-ast / parsesrc/services/mcpClient.ts— raw-ast / parsesrc/services/toolRegistry.ts— raw-ast / parsesrc/services/watchdog.ts— raw-ast / parsesrc/stores/chatStore.ts— raw-ast / parsesrc/stores/combatStore.ts— raw-ast / parsesrc/stores/gameStateStore.ts— raw-ast / parse
Tools
- inventory 0.1.0 — completed
- tavernkeeper-static 5 — completed
- gitleaks 8.30.1 — completed
- opengrep 1.26.0 — completed
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1 — completed
- osv-scanner 2.4.0 — completed
- zizmor 1.28.0 — completed
- malcontent 1.25.7 — completed
Limitations
- This advisory review cannot prove the absence of unknown behavior.
- OpenGrep could not parse some source files; findings from successfully analyzed files are included.
- JavaScript analysis was incomplete, so this first-filter scan supports no clean conclusion about unobserved behavior.