No material or immediate-danger item was identified.
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Minor caution · high confidence
The README tells users to download and run an install script in one step. This is common but means users cannot inspect the script before it runs, and a compromised server could serve malicious code. The risk is low because users manually choose to run the command and the project also offers direct downloads.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: low · Exploitability: unlikely
Developer action: Consider providing a checksum-verified download step or instructing users to download and inspect the install script before executing it. Alternatively, recommend the direct release archive downloads already listed in the README as the primary installation method.
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- README.md:39-40
Contextual expected matches (10)
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation tells users to download and run the project's own install script. This is a standard, visible install method used by many open-source projects. The user manually copies and runs the command, and the docs explain what the script does.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/de/docs/installation.md:43-44
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation tells users to download and run the project's own install script with a custom folder option. This is a standard, visible install method. The user manually runs the command.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/docs/installation.md:94-95
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation shows the same install command with an option to choose a custom install folder. This is a standard, visible install method. The user manually runs it and the docs explain what happens.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/ru/docs/installation.md:94-95
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation tells users to download and run the project's own install script. This is a standard, visible install method used by many open-source projects. The user manually copies and runs the command.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/ru/docs/installation.md:43-44
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation tells users to download and run the project's own install script. This is a standard, visible install method used by many open-source projects. The user manually copies and runs the command.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/es/docs/installation.md:43-44
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation shows the same install command with an option to choose a custom install folder. This is a standard, visible install method. The user manually runs it and the docs explain what happens.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/es/docs/installation.md:94-95
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation shows the same install command with an option to choose a custom install folder. This is a standard, visible install method. The user manually runs it and the docs explain what happens.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/de/docs/installation.md:94-95
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation tells users to download and run the project's own install script. This is a standard, visible install method used by many open-source projects. The user manually copies and runs the command.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/docs/installation.md:43-44
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation tells users to download and run the project's own install script. This is a standard, visible install method used by many open-source projects. The user manually copies and runs the command.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/fr/docs/installation.md:43-44
OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline
Expected behavior · high confidence
The documentation shows the same install command with an option to choose a custom install folder. This is a standard, visible install method. The user manually runs it and the docs explain what happens.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.download-and-execute.shell-pipeline
- File role
- documentation
- Source
- docs-site/docs/fr/docs/installation.md:94-95