What this review found
Dependency advisory GHSA-5xrq-8626-4rwp applies
Material concern · high confidence
A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.
Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a critical security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5xrq-8626-4rwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v6wh-96g9-6wx3 applies
Material concern · high confidence
A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.
Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a medium security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6wh-96g9-6wx3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-25h7-pfq9-p65f applies
Material concern · high confidence
A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-25h7-pfq9-p65f to a dependency declared by this repository.
Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-25h7-pfq9-p65f
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4w7w-66w2-5vf9 applies
Material concern · high confidence
A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.
Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a medium security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4w7w-66w2-5vf9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Material concern · high confidence
A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Material concern · high confidence
A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7r86-cg39-jmmj applies
Material concern · high confidence
A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-6g55-p6wh-862q applies
Material concern · high confidence
A tool used only for testing the software has a known security flaw. It does not affect the actual extension that users install, but it could pose a risk to the developer's build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: The lockfile for the vectfox-tests package declares a transitive dependency matching a high security advisory. The root package only defines devDependencies for testing frameworks, so this vulnerable package is restricted to the development and CI environments and is not shipped to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected testing dependencies to patched versions using npm audit fix or by upgrading the root devDependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6g55-p6wh-862q
- File role
- production
- Source
- package-lock.json
Minor cautions
Dependency advisory GHSA-67mh-4wv8-2f99 applies
Minor caution · medium confidence
A testing tool used by the developer has a known security issue in one of its sub-components. This only affects the developer's test setup, not the actual extension that users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-67mh-4wv8-2f99 to a dependency declared by this repository.
Contextual assessment: A known advisory was matched against a dependency declared in the vectfox-tests package-lock.json. This lockfile contains only devDependencies (Playwright, Vitest, jsdom, jieba-wasm) and no production runtime dependencies. The vulnerable package is a transitive dependency of a testing framework, so it does not ship with or execute in the extension itself. The advisory represents supply-chain hygiene debt in the development environment rather than a runtime risk to extension users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; run npm audit fix or bump the relevant testing framework version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-67mh-4wv8-2f99
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rf6f-7fwh-wjgh applies
Minor caution · medium confidence
A testing tool has a serious known flaw, but because it is only used during development and testing, it does not affect the extension that users actually run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency in the vectfox-tests lockfile. Despite the advisory severity, the lockfile is for a test-only package whose root declares exclusively devDependencies. The vulnerable transitive dependency is part of a testing framework toolchain and is not bundled into the extension's production code or executed at runtime for end users. Exploitation would require attacking the developer's local or CI test environment, not the deployed extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency tree to a patched version; prioritize this among the other dev-dependency advisories due to the higher advisory severity.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rf6f-7fwh-wjgh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · medium confidence
A high-severity flaw exists in a sub-component of a testing tool, but it only impacts the developer's test environment, not the installed extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a transitive dependency in the vectfox-tests lockfile. The root package declares only devDependencies for testing frameworks. The vulnerable package does not appear in the extension's production runtime path. Exploitation is constrained to the development or CI environment and does not expose extension users to the vulnerability.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version; treat with reasonable priority given the high advisory severity.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · medium confidence
A testing tool has a moderate known issue in one of its components. This only affects the developer's test setup, not the extension itself.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency in the vectfox-tests lockfile. The lockfile root declares only devDependencies for testing tooling. The vulnerable transitive package is not part of the extension's production bundle or runtime. This is development-environment supply-chain hygiene debt with no direct path to end-user impact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mw96-cpmx-2vgc applies
Minor caution · medium confidence
A serious flaw was found in a sub-component of a testing tool. Since it is only used during development, it does not affect the extension users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a transitive dependency in the vectfox-tests lockfile. The root package declares only devDependencies for testing frameworks such as Playwright and Vitest. The vulnerable package is not shipped with or executed by the extension at runtime. Exploitation would require compromise of the developer's test or CI environment, not the deployed extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency tree to a patched version; prioritize due to the high advisory severity.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mw96-cpmx-2vgc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · medium confidence
A testing tool has a moderate known issue in one of its sub-components. This only affects the developer's test setup, not the extension itself.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency in the vectfox-tests lockfile. The lockfile root declares only devDependencies for testing tooling. The vulnerable transitive package is not part of the extension's production runtime. This is development-environment supply-chain hygiene debt with no direct path to end-user impact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qx2v-qp2m-jg93 applies
Minor caution · medium confidence
A testing tool has a moderate known issue in one of its sub-components. This only affects the developer's test setup, not the extension itself.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency in the vectfox-tests lockfile. The lockfile root declares only devDependencies for testing tooling. The vulnerable transitive package is not part of the extension's production runtime. This is development-environment supply-chain hygiene debt with no direct path to end-user impact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qx2v-qp2m-jg93
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · medium confidence
A testing tool has a moderate known issue in one of its sub-components. This only affects the developer's test setup, not the extension itself.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency in the vectfox-tests lockfile. The lockfile root declares only devDependencies for testing tooling. The vulnerable transitive package is not part of the extension's production runtime. This is development-environment supply-chain hygiene debt with no direct path to end-user impact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-96hv-2xvq-fx4p applies
Minor caution · medium confidence
A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-96hv-2xvq-fx4p to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-96hv-2xvq-fx4p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-58qx-3vcg-4xpx applies
Minor caution · medium confidence
A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-58qx-3vcg-4xpx to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-58qx-3vcg-4xpx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fx2h-pf6j-xcff applies
Minor caution · medium confidence
A security scanner found known issues in some of the tools used to test the project. Because these are testing tools and not part of the actual extension that runs in SillyTavern, they don't pose a direct risk to users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory for a dependency in the package-lock.json. The lockfile context indicates this is for the 'vectfox-tests' package, which only declares devDependencies. These vulnerabilities are confined to the development and testing environment and do not affect the runtime of the SillyTavern extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected development dependencies to their latest patched versions to maintain a secure build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fx2h-pf6j-xcff
- File role
- production
- Source
- package-lock.json
Expected scanner matches (0)
None.