TavernKeeper Scan Report
paradox460/ST-MessageSplit
Commit 2daade1 Reviewed
No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger 0 material 3 low
What this review found
No material or immediate-danger item was identified.
Deterministic technical evidence (3)
-
Dependency advisory GHSA-mh99-v99m-4gvg:pkg:4ccc458e17e9edf57fcb5743 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: bun.lock
-
Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:46968ba7f775ec580db4bbb2 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: bun.lock
-
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:d9de591f6b7272d0d17e4e9f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: bun.lock
Coverage and limitations
JavaScript coverage
Unresolved JavaScript stages
dist/index.js— derived-ast / parsedist/index.js— normalize / unsupportedsrc/buttons.ts— raw-ast / parsesrc/commands.ts— raw-ast / parsesrc/global.d.ts— raw-ast / parsesrc/index.ts— raw-ast / parsesrc/mutations.ts— raw-ast / parsesrc/segment.ts— raw-ast / parsesrc/session.ts— derived-ast / parsesrc/session.ts— normalize / unsupportedsrc/session.ts— raw-ast / parsesrc/util.ts— raw-ast / parsetest/commands.test.ts— raw-ast / parsetest/helpers.ts— raw-ast / parsetest/mutations.test.ts— raw-ast / parsetest/preload.ts— raw-ast / parse
Tools
- inventory 0.1.0 — completed
- tavernkeeper-static 5 — completed
- gitleaks 8.30.1 — completed
- opengrep 1.26.0 — completed
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1 — completed
- osv-scanner 2.4.0 — completed
- zizmor 1.28.0 — not-applicable
- malcontent 1.25.7 — completed
Limitations
- This advisory review cannot prove the absence of unknown behavior.
- JavaScript analysis was incomplete, so this first-filter scan supports no clean conclusion about unobserved behavior.