TavernKeeper Scan Report

SammCheese/SillyTavern-Discordia

Commit b8558fc Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 15 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-g7r4-m6w7-qqqr applies

Minor caution · high confidence

The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-g7r4-m6w7-qqqr to a dependency declared by this repository.

Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected development dependency to a patched version to keep the build environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-g7r4-m6w7-qqqr
File role
production
Source
bun.lock

Dependency advisory GHSA-rf6f-7fwh-wjgh applies

Minor caution · high confidence

The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.

Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected development dependency to a patched version to keep the build environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rf6f-7fwh-wjgh
File role
production
Source
bun.lock

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · high confidence

The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected development dependency to a patched version to keep the build environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
bun.lock

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · high confidence

The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected development dependency to a patched version to keep the build environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
bun.lock

Dependency advisory GHSA-jxxr-4gwj-5jf2 applies

Minor caution · high confidence

The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-jxxr-4gwj-5jf2 to a dependency declared by this repository.

Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected development dependency to a patched version to keep the build environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-jxxr-4gwj-5jf2
File role
production
Source
bun.lock

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · high confidence

The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected development dependency to a patched version to keep the build environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
bun.lock

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · high confidence

The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected development dependency to a patched version to keep the build environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
bun.lock

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Minor caution · high confidence

The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected development dependency to a patched version to keep the build environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
bun.lock

Dependency advisory GHSA-2p49-hgcm-8545 applies

Minor caution · low confidence

A security scanner flagged a dependency in this project's lockfile as having a known vulnerability. This extension is a visual theme for SillyTavern with no access to passwords, API keys, or server functions, so the practical risk to users is low. The flagged package is most likely a build tool that never runs on end-user machines.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2p49-hgcm-8545 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency resolved in bun.lock. The project is a frontend-only SillyTavern UI theme extension that ships compiled dist/bundle.js and dist/style.css. The visible direct dependencies are React UI libraries and the devDependencies are build tooling (Vite, ESLint, Tailwind, etc.). Without the specific package identity it is not possible to confirm runtime reachability, but the project has no server-side component, no credential handling, and no external API calls in its stated purpose. Advisory severity alone does not establish user harm in this context.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient, but no urgent action is required for this frontend-only extension.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2p49-hgcm-8545
File role
production
Source
bun.lock

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Minor caution · low confidence

Another dependency in the lockfile was flagged. Since this is a purely visual extension and the flagged package is likely a development or build tool, the real-world danger to people using the extension is minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in bun.lock. The extension ships only compiled frontend assets. The project purpose is a Discord-themed UI overlay for SillyTavern with no credential, network, or persistence capabilities beyond standard UI rendering. The advisory's severity does not by itself demonstrate exploitable runtime reachability in this deployment model.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
bun.lock

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · low confidence

A third dependency was flagged by the scanner. The extension is a theme with no sensitive data access, so the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency resolved in bun.lock. The project is a frontend UI theme with compiled output. No evidence of server-side processing, credential handling, or attacker-controlled input reaching vulnerable code paths is present in the supplied context.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
bun.lock

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · low confidence

A fourth dependency was flagged. As with the others, this is a visual extension with no sensitive functions, so the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in bun.lock. The extension is a compiled frontend theme for SillyTavern. The advisory severity does not translate to user harm without runtime reachability and attacker-controlled input, neither of which is evident in this frontend-only project.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
bun.lock

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · low confidence

A medium-severity dependency flag was raised. This extension is a visual theme with no access to sensitive data, so the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency in bun.lock. The project is a frontend-only UI theme extension shipping compiled assets. No runtime reachability or attacker-controlled input path is evident in the supplied context for this advisory to produce concrete user harm.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
bun.lock
Expected scanner matches (2)

Gitleaks reported generic-api-key

Expected behavior · high confidence

The scanner thought it found a secret password or key, but the flagged line is just normal code that sets up the extension's public interface. There is no hidden credential here.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
production
Source
src/apis/extensionAPI.ts:499

Gitleaks reported generic-api-key

Expected behavior · high confidence

The scanner flagged this line because it saw words that look like they could be related to API keys. However, the line is just a code definition describing how the extension's API works. There is no secret or password here.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: The gitleaks generic-api-key rule matched on line 31, which contains a TypeScript type annotation declaring a property named api of type DiscordiaAPIv1 within an interface definition. This is a static type declaration in source code, not a hardcoded credential, token, or secret value. No sensitive data is present, and the matched text is a type reference with no runtime credential exposure.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
production
Source
src/apis/extensionAPI.ts:31

Coverage and limitations

Tools

Limitations

Technical scan identity