What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-xj6q-8x83-jv6g applies
Minor caution · low confidence
A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xj6q-8x83-jv6g to a dependency declared by this repository.
Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application like this, lockfile advisories are typically associated with development dependencies (e.g., Vite, ESLint) or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.
Impact: none · Exploitability: unlikely
Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xj6q-8x83-jv6g
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-395f-4hp3-45gv applies
Minor caution · low confidence
A scanner found a high-severity issue in a package. Because the project runs locally on the user's machine rather than as a public web service, this is likely a problem in the developer's build tools rather than something that can attack the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-395f-4hp3-45gv to a dependency declared by this repository.
Contextual assessment: A high-severity dependency advisory was matched in the lockfile, but package details were redacted. For a local-first Electron and Vite application, high-severity advisories are frequently associated with development tooling or build steps rather than production runtime code reachable by untrusted inputs.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged dependency and upgrade it to a secure version, ensuring build tools and dependencies remain current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-395f-4hp3-45gv
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-jr45-8vmc-qm54 applies
Minor caution · low confidence
A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-jr45-8vmc-qm54 to a dependency declared by this repository.
Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.
Impact: none · Exploitability: unlikely
Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-jr45-8vmc-qm54
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-hcpx-6fm6-wx23 applies
Minor caution · low confidence
A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hcpx-6fm6-wx23 to a dependency declared by this repository.
Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.
Impact: none · Exploitability: unlikely
Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hcpx-6fm6-wx23
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f4gw-2p7v-4548 applies
Minor caution · low confidence
A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f4gw-2p7v-4548 to a dependency declared by this repository.
Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.
Impact: none · Exploitability: unlikely
Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f4gw-2p7v-4548
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7q8q-rj6j-mhjq applies
Minor caution · low confidence
A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7q8q-rj6j-mhjq to a dependency declared by this repository.
Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.
Impact: none · Exploitability: unlikely
Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7q8q-rj6j-mhjq
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-gcfj-64vw-6mp9 applies
Minor caution · low confidence
A scanner found a high-severity issue in a package. Because the project runs locally on the user's machine rather than as a public web service, this is likely a problem in the developer's build tools rather than something that can attack the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-gcfj-64vw-6mp9 to a dependency declared by this repository.
Contextual assessment: A high-severity dependency advisory was matched in the lockfile, but package details were redacted. For a local-first Electron and Vite application, high-severity advisories are frequently associated with development tooling or build steps rather than production runtime code reachable by untrusted inputs.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged dependency and upgrade it to a secure version, ensuring build tools and dependencies remain current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-gcfj-64vw-6mp9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r4w5-6pfg-jxp5 applies
Minor caution · low confidence
A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r4w5-6pfg-jxp5 to a dependency declared by this repository.
Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.
Impact: none · Exploitability: unlikely
Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r4w5-6pfg-jxp5
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8xcm-r25x-g524 applies
Minor caution · low confidence
A scanner flagged a medium-level security issue in a dependency, but the specific package was not included in the report. The visible dependencies are development tools that don't end up in the final app, so this likely affects only the build environment, not end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8xcm-r25x-g524 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-8xcm-r25x-g524) against a dependency in the lockfile, but package details were removed so the affected package and version cannot be identified from the supplied evidence. The visible lockfile portion shows only dev-only packages (Babel, esbuild platform binaries, electron tooling). The project's production dependencies are limited to react, react-dom, @xyflow/react, and @toon-format/toon, which are well-maintained UI libraries unlikely to carry this advisory. Without identifying the specific package, runtime reachability and attacker-controlled input paths cannot be confirmed for the shipped desktop application.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8xcm-r25x-g524
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-pmv8-rq9r-6j72 applies
Minor caution · low confidence
A scanner flagged a medium-level issue in a dependency, but the affected package name was not provided. Since the visible dependencies are build-time tools that don't ship with the app, the risk to end users is likely minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-pmv8-rq9r-6j72 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-pmv8-rq9r-6j72) against a dependency in the lockfile, but package details were removed. The visible lockfile entries are all dev dependencies. The project ships as a bundled Electron desktop app built with Vite, meaning dev-only dependencies are not included in the runtime artifact. Without the specific package identity, runtime reachability in the production application cannot be established.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-pmv8-rq9r-6j72
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mmx7-hfxf-jppx applies
Minor caution · low confidence
A scanner flagged a medium-level issue in a dependency, but the specific package was not named. The visible dependencies are development tools, so this most likely affects the build environment rather than the app users run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mmx7-hfxf-jppx to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-mmx7-hfxf-jppx) against a dependency in the lockfile, but package details were removed. The supplied lockfile context shows only dev-only packages. The four production dependencies are mainstream React ecosystem libraries. Without identifying the affected package, it is not possible to confirm whether vulnerable code is reachable in the shipped Electron application or whether attacker-controlled input reaches it.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mmx7-hfxf-jppx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mwf2-3pr3-8698 applies
Minor caution · low confidence
A scanner flagged a medium-level issue in a dependency, but the affected package was not included in the report. The visible dependencies are build tools, so the risk to end users is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mwf2-3pr3-8698 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-mwf2-3pr3-8698) against a dependency in the lockfile, but package details were removed. The visible lockfile portion contains only dev dependencies. The project is a local-first desktop app whose production runtime consists of bundled Vite output plus Electron, not the full dependency tree. Without the specific package and version, runtime reachability cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mwf2-3pr3-8698
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · low confidence
A scanner flagged a high-level issue in a dependency, but the specific package was not named. The visible dependencies are development tools that don't ship with the final app, so the risk to end users is likely limited. The high severity rating alone does not mean users are in danger.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory (GHSA-r28c-9q8g-f849) against a dependency in the lockfile, but package details were removed. Despite the high scanner severity, the visible lockfile entries are all dev dependencies, and the project's production dependencies are minimal React ecosystem packages. The shipped artifact is a bundled Electron desktop app that does not include dev-only packages at runtime. Without the specific package identity, it is not possible to confirm that vulnerable code is reachable in the production application or that attacker-controlled input reaches it. Advisory severity alone does not establish immediate danger.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit locally to identify the specific package. If it is a dev dependency, updating is good hygiene; if it is a production dependency, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v3r7-h72x-cjcm applies
Minor caution · low confidence
A scanner flagged a medium-level issue in a dependency, but the affected package was not provided. The visible dependencies are build-time tools, so this most likely affects the development environment rather than the app itself.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v3r7-h72x-cjcm to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-v3r7-h72x-cjcm) against a dependency in the lockfile, but package details were removed. The visible lockfile context shows only dev-only packages. The production dependency set is limited to react, react-dom, @xyflow/react, and @toon-format/toon. Without the specific package and version, runtime reachability and attacker input paths cannot be confirmed for the shipped application.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v3r7-h72x-cjcm
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4cwx-7wf7-3272 applies
Minor caution · low confidence
A scanner flagged a high-level issue in a dependency, but the specific package was not named. The visible dependencies are development tools that don't ship with the final app, so the risk to end users is likely limited.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4cwx-7wf7-3272 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory (GHSA-4cwx-7wf7-3272) against a dependency in the lockfile, but package details were removed. The visible lockfile entries are all dev dependencies. The project ships as a Vite-bundled Electron desktop app, so dev-only packages are not present in the runtime artifact. Without the specific package identity, it cannot be confirmed that vulnerable code is reachable in production or that attacker-controlled input reaches it. High advisory severity alone does not establish immediate user danger.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit locally to identify the specific package. If it is a dev dependency, updating is good hygiene; if it is a production dependency, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4cwx-7wf7-3272
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-jqh4-m9w3-8hp9 applies
Minor caution · low confidence
A scanner flagged a medium-level issue in a dependency, but the affected package was not provided. The visible dependencies are build tools, so this most likely affects the development environment rather than the app users run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-jqh4-m9w3-8hp9 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-jqh4-m9w3-8hp9) against a dependency in the lockfile, but package details were removed. The visible lockfile portion shows only dev-only packages. The production dependencies are minimal and consist of well-maintained React ecosystem libraries. Without the specific package and version, runtime reachability in the shipped Electron application cannot be established.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-jqh4-m9w3-8hp9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · medium confidence
A tool used only during development has a known security issue, but it does not affect the app that users actually run on their computer.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: This advisory (GHSA-fxqj-rqcc-2cmp, medium) matches a known vulnerability in a build-tooling dependency declared in the lockfile. The project is a local-first Electron desktop app whose production runtime ships a compiled bundle; the affected package is a development/build dependency whose vulnerable code path (dev-server functionality) is not exercised in the shipped desktop application. Attacker control would require network access to a running development server, which is not part of the end-user experience.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build dependency to a patched version when convenient to keep the development environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A development tool has a serious-sounding security flaw, but because this app runs locally on your computer and does not expose a website, the flaw does not reach end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: This advisory (GHSA-mh99-v99m-4gvg, high scanner severity) corresponds to a known vulnerability in a build-tooling dependency. The project's production artifact is a bundled Electron desktop application; the vulnerable code resides in development-time tooling whose affected functionality is not present in the shipped runtime. The high scanner severity reflects the advisory's worst-case scenario for web-facing deployments, which does not apply to this local desktop app context.
Impact: low · Exploitability: unlikely
Developer action: Upgrade the flagged build dependency to a version that includes the fix.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-42h9-826w-cgv3 applies
Minor caution · medium confidence
A development-only tool has a known issue, but it is not part of the app people install and run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-42h9-826w-cgv3 to a dependency declared by this repository.
Contextual assessment: This advisory (GHSA-42h9-826w-cgv3, medium) flags a build-tooling dependency in the lockfile. The vulnerable code path is associated with development-server behavior that is not part of the compiled Electron desktop application shipped to users. Runtime reachability in the production context is absent, and attacker control over the vulnerable input would require access to a local development server.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched release during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-42h9-826w-cgv3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-m8rv-5g2x-5cg5 applies
Minor caution · medium confidence
A tool used during development has a minor known issue that does not affect the finished app.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-m8rv-5g2x-5cg5 to a dependency declared by this repository.
Contextual assessment: This advisory (GHSA-m8rv-5g2x-5cg5, medium) matches a known vulnerability in a development/build dependency. The project ships as a local Electron desktop application with a pre-built bundle; the affected tool's vulnerable functionality is confined to the development workflow and does not execute in the end-user runtime. No attacker-controlled input reaches the vulnerable code in the production context.
Impact: low · Exploitability: unlikely
Developer action: Bump the flagged development dependency to a fixed version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-m8rv-5g2x-5cg5
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A development tool has a high-severity label, but the dangerous part only exists when building the app, not when using it. Since this is a local desktop app, users are not exposed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: This advisory (GHSA-rgw5-rvv9-x895, high scanner severity) corresponds to a known vulnerability in build-tooling declared in the lockfile. The high severity reflects risk for deployments that expose the development server to network traffic. This project is a local-first Electron desktop app; the vulnerable development-server code is not included in the production bundle, and end users do not run a network-accessible dev server. Runtime reachability and attacker control are absent in the shipped context.
Impact: low · Exploitability: unlikely
Developer action: Upgrade the affected build dependency to a patched version to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-9f4c-93c8-jc8g applies
Minor caution · medium confidence
A development tool carries a high-severity warning, but the dangerous feature is only active during development and is not shipped to users of this local desktop app.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-9f4c-93c8-jc8g to a dependency declared by this repository.
Contextual assessment: This advisory (GHSA-9f4c-93c8-jc8g, high scanner severity) flags a build-tooling dependency in the lockfile. The vulnerable code path is associated with development-time server or bundler behavior that is not present in the compiled Electron desktop application. The project's local-first architecture means no network-facing service is exposed to end users, so attacker control cannot reach the vulnerable input in the production runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a version that includes the advisory fix.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-9f4c-93c8-jc8g
- File role
- production
- Source
- package-lock.json
Expected scanner matches (16)
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is just a CSS style rule that changes the mouse cursor when dragging a profile image cropper. It has nothing to do with startup persistence or security.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is part of a CSS stylesheet defining a pseudo-class selector for an active crop handle cursor state. There is no executable code, no persistence mechanism, no data flow, and no runtime behavior. This is a static style rule.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15866
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is just a styling rule for a dialog box in the app's user interface. It does not run any code or change how the app starts up.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a profile-pick dialog stage element. It contains only layout properties. There is no code execution, persistence mechanism, or startup modification behavior present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15816
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a styling rule for a heading inside a dialog. It does not affect app startup or persistence.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a profile-pick header heading element. It contains only color and font-size properties. No persistence or startup behavior is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15805
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a CSS layout rule for an image frame in a profile picture picker. It only controls how the element looks on screen.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a profile image frame container, declaring positioning, display, and touch-action properties. No executable code or persistence behavior is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15827
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a CSS style for a resize handle button on an image cropper. It only controls appearance.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a crop resize handle element with border, background, and box-shadow styling. No executable code or persistence mechanism exists in this CSS rule.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15878
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a styling rule that removes margins from text in a dialog header. It has no startup or persistence effect.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is part of a CSS selector group for profile-pick header heading and paragraph elements, setting margin to zero. No executable code or persistence mechanism exists here.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15800
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a CSS visual style for the dashed circle inside an image cropper. It only affects appearance.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a crop handle visual indicator, defining position, border, and pointer-events properties. No executable logic or persistence is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15870
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a styling rule for text margins in a dialog. It does not run code or modify startup behavior.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is part of a CSS selector group for profile-pick header heading and paragraph elements. It only sets margin to zero. No persistence or startup modification is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15801
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a layout styling rule for a dialog header. It does not affect app startup or persistence.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a profile-pick header element with flexbox layout properties. No executable code, persistence, or startup modification exists.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15791
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a styling rule for a dialog box's size and appearance. It does not run code or change startup behavior.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a profile-pick dialog container with width, height, flex, padding, border, and background properties. No persistence or startup behavior is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15778
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a CSS layout rule for the button row in a profile picture picker dialog. It only controls spacing and alignment.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a profile-pick actions container using flexbox layout properties. No code execution or persistence behavior is involved.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15892
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a CSS style for a dimming overlay on top of an image in the profile picker. It only controls visual appearance.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a semi-transparent overlay scrim, defining absolute positioning and a background color. No persistence or executable code is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15843
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a CSS style for the circular crop box in the profile picture picker. It only controls how the cropping circle looks.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for the circular crop selection box, defining position, border, border-radius, cursor, and box-shadow properties. No executable code or persistence mechanism exists.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15850
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a CSS style controlling how an image is sized inside the profile picture picker. It only affects layout.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS descendant selector for an image element inside the profile-pick frame, setting display and max-dimensions. No executable code or persistence is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15836
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a styling rule for a dark overlay behind a dialog. It does not affect app startup or persistence.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a profile-pick backdrop overlay with fixed positioning and background properties. No executable code, persistence, or startup modification exists.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15767
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
This is a styling rule for descriptive text in a dialog header. It does not run code or modify startup behavior.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The flagged line is a CSS class selector for a profile-pick header paragraph element with margin and font-size properties. No persistence or startup modification behavior is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/styles.css:15810