TavernKeeper Scan Report
RebootFlume/TipsyTavern
Commit 72a1654 Reviewed
No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger 0 material 25 low
What this review found
No material or immediate-danger item was identified.
Deterministic technical evidence (25)
-
Dependency advisory RUSTSEC-2025-0080:pkg:d9db6230dfa23e8ba0fa93cf applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0414:pkg:e12ed7daa8c1d8360f101be8 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2026-0195:pkg:f00c24d0bbe1243110fcf725 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-2v37-7h3g-55p8:pkg:bcb01fa3f22fe943388f7142 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2024-0411:pkg:7048d8a9d3d0f0ec2dd07bfe applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0370:pkg:9b268f40461da81c7a1c55ed applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0413:pkg:c2f358c9f3bc98a14e0c2abf applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-wrw7-89jp-8q8g:pkg:4b30aae73f1836d87a5b008c applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:590275f7f1e65a0bda08b540 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2026-0221:pkg:44eb386acc1a4f9a94166f13 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2025-0081:pkg:5c764120c78ffcfe5027b39c applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2026-0194:pkg:8eeea84c983209a8f5488794 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0429:pkg:d2e88fc02f6be9987f66e6e8 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2025-0100:pkg:bd8adf60c37242745cb633a0 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0418:pkg:b245323ca01b322dae07bf9b applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0420:pkg:d1377594ef97b5997d1bd6e4 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0415:pkg:7feb02dbce543e0572f8f169 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2025-0075:pkg:3e15a087e2f1d00bbc8d944a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2025-0098:pkg:bc6e2fc910a7ca702c31e56a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2024-0416:pkg:c8c328b18837aef0f997eeec applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: package-lock.json
-
Dependency advisory RUSTSEC-2024-0419:pkg:694df782baf029578982f056 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0412:pkg:4216c3e2f95d873b67813c23 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
-
Dependency advisory RUSTSEC-2024-0417:pkg:38b1a8e2b331be3a60dc921d applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: src-tauri/Cargo.lock
Coverage and limitations
JavaScript coverage
Unresolved JavaScript stages
src/App.tsx— raw-ast / parsesrc/components/ActivityBar.tsx— raw-ast / parsesrc/components/ThemeProvider.tsx— raw-ast / parsesrc/features/characters/CharacterList.tsx— raw-ast / parsesrc/features/characters/CharacterWorkspace.tsx— raw-ast / parsesrc/features/characters/WorldBookComboBox.tsx— raw-ast / parsesrc/features/chat/ChatList.tsx— raw-ast / parsesrc/features/chat/ChatWorkspace.tsx— raw-ast / parsesrc/features/inspector/InspectorList.tsx— raw-ast / parsesrc/features/inspector/InspectorWorkspace.tsx— raw-ast / parsesrc/features/personas/PersonaList.tsx— raw-ast / parsesrc/features/personas/PersonaWorkspace.tsx— raw-ast / parsesrc/features/settings/SettingsList.tsx— raw-ast / parsesrc/features/settings/SettingsWorkspace.tsx— raw-ast / parsesrc/features/worldbook/WorldBookList.tsx— raw-ast / parsesrc/features/worldbook/WorldBookWorkspace.tsx— raw-ast / parsesrc/lib/active-stream.ts— raw-ast / parsesrc/lib/characters.ts— raw-ast / parsesrc/lib/chats.ts— raw-ast / parsesrc/lib/generate.ts— raw-ast / parsesrc/lib/inspector.ts— raw-ast / parsesrc/lib/personas.ts— raw-ast / parsesrc/lib/providers.ts— raw-ast / parsesrc/lib/settings.ts— raw-ast / parsesrc/lib/worldbooks.ts— raw-ast / parsesrc/main.tsx— raw-ast / parsesrc/types.ts— raw-ast / parse
Tools
- inventory 0.1.0 — completed
- tavernkeeper-static 5 — completed
- gitleaks 8.30.1 — completed
- opengrep 1.26.0 — completed
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1 — completed
- osv-scanner 2.4.0 — completed
- zizmor 1.28.0 — not-applicable
- malcontent 1.25.7 — not-applicable
Limitations
- This advisory review cannot prove the absence of unknown behavior.
- JavaScript analysis was incomplete, so this first-filter scan supports no clean conclusion about unobserved behavior.