This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.
0 high4 material4 low
What this review found
Dependency advisory GHSA-5xrq-8626-4rwp applies
Material concern · medium confidence
A development tool has a serious known security flaw. It probably does not reach end users, but it could put the developer's build environment at risk.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a critical-severity advisory against a package resolved in the lockfile. The lockfile declares only devDependencies at the workspace level, and the project produces bundled dist artifacts for deployment, so the vulnerable package is most likely a transitive build-time dependency. However, a critical advisory in build tooling can still pose risk to the development environment if the vulnerable code processes untrusted input during build or test execution. Without the specific package name (removed from scanner output) and with truncated source context, the exact exploit path cannot be confirmed.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package from the full lockfile, update it or its parent dependency to a patched version, and rebuild.
A development tool has a known serious security flaw. It probably does not reach end users, but it could affect the build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and ships bundled dist files, so the vulnerable package is likely a transitive build-time dependency. A high-severity advisory in build tooling can still pose risk to the development or CI environment if the vulnerable code processes untrusted input. The specific package name was removed from scanner output and source context is truncated, so the exact exploit path cannot be confirmed.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package from the full lockfile, update it or its parent dependency to a patched version, and rebuild.
A development tool has a known serious security flaw. It probably does not reach end users, but it could affect the build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and ships bundled dist files, so the vulnerable package is likely a transitive build-time dependency. A high-severity advisory in build tooling can still pose risk to the development or CI environment. The specific package name was removed from scanner output and source context is truncated, so the exact exploit path cannot be confirmed.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package from the full lockfile, update it or its parent dependency to a patched version, and rebuild.
A development tool has a known serious security flaw. It probably does not reach end users, but it could affect the build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and ships bundled dist files, so the vulnerable package is likely a transitive build-time dependency. A high-severity advisory in build tooling can still pose risk to the development or CI environment. The specific package name was removed from scanner output and source context is truncated, so the exact exploit path cannot be confirmed.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package from the full lockfile, update it or its parent dependency to a patched version, and rebuild.
A tool used only during development has a known minor security issue. It does not affect the finished product that users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-g7r4-m6w7-qqqr to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity advisory against a package resolved in the lockfile. The lockfile's declared workspace dependencies are exclusively devDependencies (Playwright, types, dotenv, type definitions, TypeScript, Vitest). The project builds to dist/backend.js and dist/frontend.js, so lockfile-resolved packages are build-time tooling and do not ship to end users. A low-severity advisory in a dev-only transitive dependency has minimal practical impact on the deployed extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
A development tool has a known moderate security issue. It is unlikely to affect people who install the finished extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a lockfile-resolved package. All workspace-level declared dependencies are devDependencies, and the extension ships bundled dist files rather than the dependency tree. A medium-severity issue in a dev-only transitive dependency has limited practical impact on the deployed extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
A development tool has a known moderate security issue. It should not affect users of the finished extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and the project deploys bundled dist artifacts, so the vulnerable package is build-time tooling that does not ship to end users. Medium-severity dev-only vulnerabilities have low practical impact on the deployed extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
A development tool has a known moderate security issue. It is unlikely to affect users of the finished extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and the project deploys bundled dist artifacts, so the vulnerable package is build-time tooling that does not ship to end users. Medium-severity dev-only vulnerabilities have low practical impact on the deployed extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.