TavernKeeper Scan Report

KritBlade/VectFox

Commit 785a3ae Reviewed

8 material concerns identified.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 high 8 material 16 low

What this review found

Dependency advisory GHSA-5xrq-8626-4rwp applies

Material concern · high confidence

A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.

Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a critical security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5xrq-8626-4rwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v6wh-96g9-6wx3 applies

Material concern · high confidence

A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.

Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a medium security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6wh-96g9-6wx3
File role
production
Source
package-lock.json

Dependency advisory GHSA-25h7-pfq9-p65f applies

Material concern · high confidence

A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-25h7-pfq9-p65f to a dependency declared by this repository.

Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-25h7-pfq9-p65f
File role
production
Source
package-lock.json

Dependency advisory GHSA-4w7w-66w2-5vf9 applies

Material concern · high confidence

A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.

Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a medium security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4w7w-66w2-5vf9
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Material concern · high confidence

A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Material concern · high confidence

A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Material concern · high confidence

A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-6g55-p6wh-862q applies

Material concern · high confidence

A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.

Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6g55-p6wh-862q
File role
production
Source
package-lock.json

Minor cautions

Dependency advisory GHSA-67mh-4wv8-2f99 applies

Minor caution · medium confidence

A testing tool used by the developer has a known security issue in one of its sub-components. This only affects the developer's test setup, not the actual extension that users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-67mh-4wv8-2f99 to a dependency declared by this repository.

Contextual assessment: A known advisory was matched against a dependency declared in the vectfox-tests package-lock.json. This lockfile contains only devDependencies (Playwright, Vitest, jsdom, jieba-wasm) and no production runtime dependencies. The vulnerable package is a transitive dependency of a testing framework, so it does not ship with or execute in the extension itself. The advisory represents supply-chain hygiene debt in the development environment rather than a runtime risk to extension users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient; run npm audit fix or bump the relevant testing framework version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-67mh-4wv8-2f99
File role
production
Source
package-lock.json

Dependency advisory GHSA-rf6f-7fwh-wjgh applies

Minor caution · medium confidence

A testing tool has a serious known flaw, but because it is only used during development and testing, it does not affect the extension that users actually run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency in the vectfox-tests lockfile. Despite the advisory severity, the lockfile is for a test-only package whose root declares exclusively devDependencies. The vulnerable transitive dependency is part of a testing framework toolchain and is not bundled into the extension's production code or executed at runtime for end users. Exploitation would require attacking the developer's local or CI test environment, not the deployed extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency tree to a patched version; prioritize this among the other dev-dependency advisories due to the higher advisory severity.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rf6f-7fwh-wjgh
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · medium confidence

A high-severity flaw exists in a sub-component of a testing tool, but it only impacts the developer's test environment, not the installed extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a transitive dependency in the vectfox-tests lockfile. The root package declares only devDependencies for testing frameworks. The vulnerable package does not appear in the extension's production runtime path. Exploitation is constrained to the development or CI environment and does not expose extension users to the vulnerability.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version; treat with reasonable priority given the high advisory severity.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · medium confidence

A testing tool has a moderate known issue in one of its components. This only affects the developer's test setup, not the extension itself.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency in the vectfox-tests lockfile. The lockfile root declares only devDependencies for testing tooling. The vulnerable transitive package is not part of the extension's production bundle or runtime. This is development-environment supply-chain hygiene debt with no direct path to end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-mw96-cpmx-2vgc applies

Minor caution · medium confidence

A serious flaw was found in a sub-component of a testing tool. Since it is only used during development, it does not affect the extension users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a transitive dependency in the vectfox-tests lockfile. The root package declares only devDependencies for testing frameworks such as Playwright and Vitest. The vulnerable package is not shipped with or executed by the extension at runtime. Exploitation would require compromise of the developer's test or CI environment, not the deployed extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency tree to a patched version; prioritize due to the high advisory severity.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mw96-cpmx-2vgc
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · medium confidence

A testing tool has a moderate known issue in one of its sub-components. This only affects the developer's test setup, not the extension itself.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency in the vectfox-tests lockfile. The lockfile root declares only devDependencies for testing tooling. The vulnerable transitive package is not part of the extension's production runtime. This is development-environment supply-chain hygiene debt with no direct path to end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-qx2v-qp2m-jg93 applies

Minor caution · medium confidence

A testing tool has a moderate known issue in one of its sub-components. This only affects the developer's test setup, not the extension itself.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency in the vectfox-tests lockfile. The lockfile root declares only devDependencies for testing tooling. The vulnerable transitive package is not part of the extension's production runtime. This is development-environment supply-chain hygiene debt with no direct path to end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qx2v-qp2m-jg93
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · medium confidence

A testing tool has a moderate known issue in one of its sub-components. This only affects the developer's test setup, not the extension itself.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency in the vectfox-tests lockfile. The lockfile root declares only devDependencies for testing tooling. The vulnerable transitive package is not part of the extension's production runtime. This is development-environment supply-chain hygiene debt with no direct path to end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-96hv-2xvq-fx4p applies

Minor caution · medium confidence

A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-96hv-2xvq-fx4p to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-96hv-2xvq-fx4p
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Minor caution · medium confidence

A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-58qx-3vcg-4xpx applies

Minor caution · medium confidence

A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-58qx-3vcg-4xpx to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-58qx-3vcg-4xpx
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Minor caution · medium confidence

A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json

Dependency advisory GHSA-fx2h-pf6j-xcff applies

Minor caution · medium confidence

A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fx2h-pf6j-xcff
File role
production
Source
package-lock.json
Expected scanner matches (0)

None.

Related contextual observations

All OSV findings are in a test-only lockfile with no production runtime dependencies

low risk · medium confidence

All eight security alerts are in a separate test-only package that the developer uses to run automated tests. The actual VectFox extension that users install does not include any of these vulnerable components. The developer should still update the test tools, but users are not at risk.

Technical assessment

The reviewed lockfile belongs to the vectfox-tests package, whose root declares only devDependencies: Playwright, Vitest coverage and UI packages, jieba-wasm, jsdom, and vitest. Every matched advisory targets a transitive dependency within this testing toolchain. None of these packages are part of the VectFox extension's production runtime code. The advisories represent development-environment supply-chain hygiene debt. While some advisories carry high severity ratings, the exploitability in this context is limited to the developer's local or CI test environment and does not create a path to compromise extension users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or manually bump the testing framework versions to resolve the advisories. Consider setting up automated dependency scanning in CI to catch these earlier.

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity