TavernKeeper Scan Report

AMousePad/Hone

Commit 0538b85 Reviewed

4 material concerns identified.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 high 4 material 4 low

What this review found

Dependency advisory GHSA-5xrq-8626-4rwp applies

Material concern · medium confidence

A development tool has a serious known security flaw. It probably does not reach end users, but it could put the developer's build environment at risk.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a critical-severity advisory against a package resolved in the lockfile. The lockfile declares only devDependencies at the workspace level, and the project produces bundled dist artifacts for deployment, so the vulnerable package is most likely a transitive build-time dependency. However, a critical advisory in build tooling can still pose risk to the development environment if the vulnerable code processes untrusted input during build or test execution. Without the specific package name (removed from scanner output) and with truncated source context, the exact exploit path cannot be confirmed.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package from the full lockfile, update it or its parent dependency to a patched version, and rebuild.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5xrq-8626-4rwp
File role
production
Source
bun.lock

Dependency advisory GHSA-r28c-9q8g-f849 applies

Material concern · medium confidence

A development tool has a known serious security flaw. It probably does not reach end users, but it could affect the build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and ships bundled dist files, so the vulnerable package is likely a transitive build-time dependency. A high-severity advisory in build tooling can still pose risk to the development or CI environment if the vulnerable code processes untrusted input. The specific package name was removed from scanner output and source context is truncated, so the exact exploit path cannot be confirmed.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package from the full lockfile, update it or its parent dependency to a patched version, and rebuild.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
bun.lock

Dependency advisory GHSA-fx2h-pf6j-xcff applies

Material concern · medium confidence

A development tool has a known serious security flaw. It probably does not reach end users, but it could affect the build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and ships bundled dist files, so the vulnerable package is likely a transitive build-time dependency. A high-severity advisory in build tooling can still pose risk to the development or CI environment. The specific package name was removed from scanner output and source context is truncated, so the exact exploit path cannot be confirmed.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package from the full lockfile, update it or its parent dependency to a patched version, and rebuild.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fx2h-pf6j-xcff
File role
production
Source
bun.lock

Dependency advisory GHSA-6g55-p6wh-862q applies

Material concern · medium confidence

A development tool has a known serious security flaw. It probably does not reach end users, but it could affect the build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and ships bundled dist files, so the vulnerable package is likely a transitive build-time dependency. A high-severity advisory in build tooling can still pose risk to the development or CI environment. The specific package name was removed from scanner output and source context is truncated, so the exact exploit path cannot be confirmed.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package from the full lockfile, update it or its parent dependency to a patched version, and rebuild.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6g55-p6wh-862q
File role
production
Source
bun.lock

Minor cautions

Dependency advisory GHSA-g7r4-m6w7-qqqr applies

Minor caution · medium confidence

A tool used only during development has a known minor security issue. It does not affect the finished product that users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-g7r4-m6w7-qqqr to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity advisory against a package resolved in the lockfile. The lockfile's declared workspace dependencies are exclusively devDependencies (Playwright, types, dotenv, type definitions, TypeScript, Vitest). The project builds to dist/backend.js and dist/frontend.js, so lockfile-resolved packages are build-time tooling and do not ship to end users. A low-severity advisory in a dev-only transitive dependency has minimal practical impact on the deployed extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-g7r4-m6w7-qqqr
File role
production
Source
bun.lock

Dependency advisory GHSA-qx2v-qp2m-jg93 applies

Minor caution · medium confidence

A development tool has a known moderate security issue. It is unlikely to affect people who install the finished extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a lockfile-resolved package. All workspace-level declared dependencies are devDependencies, and the extension ships bundled dist files rather than the dependency tree. A medium-severity issue in a dev-only transitive dependency has limited practical impact on the deployed extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qx2v-qp2m-jg93
File role
production
Source
bun.lock

Dependency advisory GHSA-v6wh-96g9-6wx3 applies

Minor caution · medium confidence

A development tool has a known moderate security issue. It should not affect users of the finished extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and the project deploys bundled dist artifacts, so the vulnerable package is build-time tooling that does not ship to end users. Medium-severity dev-only vulnerabilities have low practical impact on the deployed extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6wh-96g9-6wx3
File role
production
Source
bun.lock

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · medium confidence

A development tool has a known moderate security issue. It is unlikely to affect users of the finished extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a lockfile-resolved package. The workspace declares only devDependencies and the project deploys bundled dist artifacts, so the vulnerable package is build-time tooling that does not ship to end users. Medium-severity dev-only vulnerabilities have low practical impact on the deployed extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
bun.lock
Expected scanner matches (0)

None.

Coverage and limitations

Tools

Limitations

Technical scan identity