TavernKeeper Scan Report

unrefined803/RPGraph

Commit 2fa4ba4 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 40 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-xj6q-8x83-jv6g applies

Minor caution · low confidence

A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xj6q-8x83-jv6g to a dependency declared by this repository.

Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application like this, lockfile advisories are typically associated with development dependencies (e.g., Vite, ESLint) or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.

Impact: none · Exploitability: unlikely

Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xj6q-8x83-jv6g
File role
production
Source
package-lock.json

Dependency advisory GHSA-395f-4hp3-45gv applies

Minor caution · low confidence

A scanner found a high-severity issue in a package. Because the project runs locally on the user's machine rather than as a public web service, this is likely a problem in the developer's build tools rather than something that can attack the user.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-395f-4hp3-45gv to a dependency declared by this repository.

Contextual assessment: A high-severity dependency advisory was matched in the lockfile, but package details were redacted. For a local-first Electron and Vite application, high-severity advisories are frequently associated with development tooling or build steps rather than production runtime code reachable by untrusted inputs.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged dependency and upgrade it to a secure version, ensuring build tools and dependencies remain current.

Scanner
osv-scanner 2.4.0
Rule
GHSA-395f-4hp3-45gv
File role
production
Source
package-lock.json

Dependency advisory GHSA-jr45-8vmc-qm54 applies

Minor caution · low confidence

A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-jr45-8vmc-qm54 to a dependency declared by this repository.

Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.

Impact: none · Exploitability: unlikely

Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-jr45-8vmc-qm54
File role
production
Source
package-lock.json

Dependency advisory GHSA-hcpx-6fm6-wx23 applies

Minor caution · low confidence

A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-hcpx-6fm6-wx23 to a dependency declared by this repository.

Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.

Impact: none · Exploitability: unlikely

Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-hcpx-6fm6-wx23
File role
production
Source
package-lock.json

Dependency advisory GHSA-f4gw-2p7v-4548 applies

Minor caution · low confidence

A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f4gw-2p7v-4548 to a dependency declared by this repository.

Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.

Impact: none · Exploitability: unlikely

Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f4gw-2p7v-4548
File role
production
Source
package-lock.json

Dependency advisory GHSA-7q8q-rj6j-mhjq applies

Minor caution · low confidence

A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7q8q-rj6j-mhjq to a dependency declared by this repository.

Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.

Impact: none · Exploitability: unlikely

Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7q8q-rj6j-mhjq
File role
production
Source
package-lock.json

Dependency advisory GHSA-gcfj-64vw-6mp9 applies

Minor caution · low confidence

A scanner found a high-severity issue in a package. Because the project runs locally on the user's machine rather than as a public web service, this is likely a problem in the developer's build tools rather than something that can attack the user.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-gcfj-64vw-6mp9 to a dependency declared by this repository.

Contextual assessment: A high-severity dependency advisory was matched in the lockfile, but package details were redacted. For a local-first Electron and Vite application, high-severity advisories are frequently associated with development tooling or build steps rather than production runtime code reachable by untrusted inputs.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged dependency and upgrade it to a secure version, ensuring build tools and dependencies remain current.

Scanner
osv-scanner 2.4.0
Rule
GHSA-gcfj-64vw-6mp9
File role
production
Source
package-lock.json

Dependency advisory GHSA-r4w5-6pfg-jxp5 applies

Minor caution · low confidence

A security scanner found a known weakness in a package used by the project. However, since this is a local desktop app and the package is likely a development tool or unexposed background dependency, it does not pose a direct threat to the user.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r4w5-6pfg-jxp5 to a dependency declared by this repository.

Contextual assessment: A dependency advisory was flagged in the lockfile, but package details were redacted. In a local-first desktop application, lockfile advisories are typically associated with development dependencies or unexposed transitive dependencies. Since the application does not expose remote inbound attack surfaces, runtime exploitation is unlikely.

Impact: none · Exploitability: unlikely

Developer action: Review the specific dependency flagged by this advisory and update it to a patched version if possible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r4w5-6pfg-jxp5
File role
production
Source
package-lock.json

Dependency advisory GHSA-8xcm-r25x-g524 applies

Minor caution · low confidence

A scanner flagged a medium-level security issue in a dependency, but the specific package was not included in the report. The visible dependencies are development tools that don't end up in the final app, so this likely affects only the build environment, not end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8xcm-r25x-g524 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-8xcm-r25x-g524) against a dependency in the lockfile, but package details were removed so the affected package and version cannot be identified from the supplied evidence. The visible lockfile portion shows only dev-only packages (Babel, esbuild platform binaries, electron tooling). The project's production dependencies are limited to react, react-dom, @xyflow/react, and @toon-format/toon, which are well-maintained UI libraries unlikely to carry this advisory. Without identifying the specific package, runtime reachability and attacker-controlled input paths cannot be confirmed for the shipped desktop application.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8xcm-r25x-g524
File role
production
Source
package-lock.json

Dependency advisory GHSA-pmv8-rq9r-6j72 applies

Minor caution · low confidence

A scanner flagged a medium-level issue in a dependency, but the affected package name was not provided. Since the visible dependencies are build-time tools that don't ship with the app, the risk to end users is likely minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-pmv8-rq9r-6j72 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-pmv8-rq9r-6j72) against a dependency in the lockfile, but package details were removed. The visible lockfile entries are all dev dependencies. The project ships as a bundled Electron desktop app built with Vite, meaning dev-only dependencies are not included in the runtime artifact. Without the specific package identity, runtime reachability in the production application cannot be established.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-pmv8-rq9r-6j72
File role
production
Source
package-lock.json

Dependency advisory GHSA-mmx7-hfxf-jppx applies

Minor caution · low confidence

A scanner flagged a medium-level issue in a dependency, but the specific package was not named. The visible dependencies are development tools, so this most likely affects the build environment rather than the app users run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mmx7-hfxf-jppx to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-mmx7-hfxf-jppx) against a dependency in the lockfile, but package details were removed. The supplied lockfile context shows only dev-only packages. The four production dependencies are mainstream React ecosystem libraries. Without identifying the affected package, it is not possible to confirm whether vulnerable code is reachable in the shipped Electron application or whether attacker-controlled input reaches it.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mmx7-hfxf-jppx
File role
production
Source
package-lock.json

Dependency advisory GHSA-mwf2-3pr3-8698 applies

Minor caution · low confidence

A scanner flagged a medium-level issue in a dependency, but the affected package was not included in the report. The visible dependencies are build tools, so the risk to end users is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mwf2-3pr3-8698 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-mwf2-3pr3-8698) against a dependency in the lockfile, but package details were removed. The visible lockfile portion contains only dev dependencies. The project is a local-first desktop app whose production runtime consists of bundled Vite output plus Electron, not the full dependency tree. Without the specific package and version, runtime reachability cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mwf2-3pr3-8698
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · low confidence

A scanner flagged a high-level issue in a dependency, but the specific package was not named. The visible dependencies are development tools that don't ship with the final app, so the risk to end users is likely limited. The high severity rating alone does not mean users are in danger.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory (GHSA-r28c-9q8g-f849) against a dependency in the lockfile, but package details were removed. Despite the high scanner severity, the visible lockfile entries are all dev dependencies, and the project's production dependencies are minimal React ecosystem packages. The shipped artifact is a bundled Electron desktop app that does not include dev-only packages at runtime. Without the specific package identity, it is not possible to confirm that vulnerable code is reachable in the production application or that attacker-controlled input reaches it. Advisory severity alone does not establish immediate danger.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit locally to identify the specific package. If it is a dev dependency, updating is good hygiene; if it is a production dependency, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-v3r7-h72x-cjcm applies

Minor caution · low confidence

A scanner flagged a medium-level issue in a dependency, but the affected package was not provided. The visible dependencies are build-time tools, so this most likely affects the development environment rather than the app itself.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v3r7-h72x-cjcm to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-v3r7-h72x-cjcm) against a dependency in the lockfile, but package details were removed. The visible lockfile context shows only dev-only packages. The production dependency set is limited to react, react-dom, @xyflow/react, and @toon-format/toon. Without the specific package and version, runtime reachability and attacker input paths cannot be confirmed for the shipped application.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v3r7-h72x-cjcm
File role
production
Source
package-lock.json

Dependency advisory GHSA-4cwx-7wf7-3272 applies

Minor caution · low confidence

A scanner flagged a high-level issue in a dependency, but the specific package was not named. The visible dependencies are development tools that don't ship with the final app, so the risk to end users is likely limited.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4cwx-7wf7-3272 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory (GHSA-4cwx-7wf7-3272) against a dependency in the lockfile, but package details were removed. The visible lockfile entries are all dev dependencies. The project ships as a Vite-bundled Electron desktop app, so dev-only packages are not present in the runtime artifact. Without the specific package identity, it cannot be confirmed that vulnerable code is reachable in production or that attacker-controlled input reaches it. High advisory severity alone does not establish immediate user danger.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit locally to identify the specific package. If it is a dev dependency, updating is good hygiene; if it is a production dependency, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4cwx-7wf7-3272
File role
production
Source
package-lock.json

Dependency advisory GHSA-jqh4-m9w3-8hp9 applies

Minor caution · low confidence

A scanner flagged a medium-level issue in a dependency, but the affected package was not provided. The visible dependencies are build tools, so this most likely affects the development environment rather than the app users run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-jqh4-m9w3-8hp9 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-jqh4-m9w3-8hp9) against a dependency in the lockfile, but package details were removed. The visible lockfile portion shows only dev-only packages. The production dependencies are minimal and consist of well-maintained React ecosystem libraries. Without the specific package and version, runtime reachability in the shipped Electron application cannot be established.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit locally to identify the specific package and update it if feasible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-jqh4-m9w3-8hp9
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · medium confidence

A tool used only during development has a known security issue, but it does not affect the app that users actually run on their computer.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: This advisory (GHSA-fxqj-rqcc-2cmp, medium) matches a known vulnerability in a build-tooling dependency declared in the lockfile. The project is a local-first Electron desktop app whose production runtime ships a compiled bundle; the affected package is a development/build dependency whose vulnerable code path (dev-server functionality) is not exercised in the shipped desktop application. Attacker control would require network access to a running development server, which is not part of the end-user experience.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build dependency to a patched version when convenient to keep the development environment current.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A development tool has a serious-sounding security flaw, but because this app runs locally on your computer and does not expose a website, the flaw does not reach end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: This advisory (GHSA-mh99-v99m-4gvg, high scanner severity) corresponds to a known vulnerability in a build-tooling dependency. The project's production artifact is a bundled Electron desktop application; the vulnerable code resides in development-time tooling whose affected functionality is not present in the shipped runtime. The high scanner severity reflects the advisory's worst-case scenario for web-facing deployments, which does not apply to this local desktop app context.

Impact: low · Exploitability: unlikely

Developer action: Upgrade the flagged build dependency to a version that includes the fix.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-42h9-826w-cgv3 applies

Minor caution · medium confidence

A development-only tool has a known issue, but it is not part of the app people install and run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-42h9-826w-cgv3 to a dependency declared by this repository.

Contextual assessment: This advisory (GHSA-42h9-826w-cgv3, medium) flags a build-tooling dependency in the lockfile. The vulnerable code path is associated with development-server behavior that is not part of the compiled Electron desktop application shipped to users. Runtime reachability in the production context is absent, and attacker control over the vulnerable input would require access to a local development server.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched release during routine maintenance.

Scanner
osv-scanner 2.4.0
Rule
GHSA-42h9-826w-cgv3
File role
production
Source
package-lock.json

Dependency advisory GHSA-m8rv-5g2x-5cg5 applies

Minor caution · medium confidence

A tool used during development has a minor known issue that does not affect the finished app.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-m8rv-5g2x-5cg5 to a dependency declared by this repository.

Contextual assessment: This advisory (GHSA-m8rv-5g2x-5cg5, medium) matches a known vulnerability in a development/build dependency. The project ships as a local Electron desktop application with a pre-built bundle; the affected tool's vulnerable functionality is confined to the development workflow and does not execute in the end-user runtime. No attacker-controlled input reaches the vulnerable code in the production context.

Impact: low · Exploitability: unlikely

Developer action: Bump the flagged development dependency to a fixed version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-m8rv-5g2x-5cg5
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A development tool has a high-severity label, but the dangerous part only exists when building the app, not when using it. Since this is a local desktop app, users are not exposed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: This advisory (GHSA-rgw5-rvv9-x895, high scanner severity) corresponds to a known vulnerability in build-tooling declared in the lockfile. The high severity reflects risk for deployments that expose the development server to network traffic. This project is a local-first Electron desktop app; the vulnerable development-server code is not included in the production bundle, and end users do not run a network-accessible dev server. Runtime reachability and attacker control are absent in the shipped context.

Impact: low · Exploitability: unlikely

Developer action: Upgrade the affected build dependency to a patched version to protect the development environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json

Dependency advisory GHSA-9f4c-93c8-jc8g applies

Minor caution · medium confidence

A development tool carries a high-severity warning, but the dangerous feature is only active during development and is not shipped to users of this local desktop app.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-9f4c-93c8-jc8g to a dependency declared by this repository.

Contextual assessment: This advisory (GHSA-9f4c-93c8-jc8g, high scanner severity) flags a build-tooling dependency in the lockfile. The vulnerable code path is associated with development-time server or bundler behavior that is not present in the compiled Electron desktop application. The project's local-first architecture means no network-facing service is exposed to end users, so attacker control cannot reach the vulnerable input in the production runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a version that includes the advisory fix.

Scanner
osv-scanner 2.4.0
Rule
GHSA-9f4c-93c8-jc8g
File role
production
Source
package-lock.json
Expected scanner matches (16)

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is just a CSS style rule that changes the mouse cursor when dragging a profile image cropper. It has nothing to do with startup persistence or security.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is part of a CSS stylesheet defining a pseudo-class selector for an active crop handle cursor state. There is no executable code, no persistence mechanism, no data flow, and no runtime behavior. This is a static style rule.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15866

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is just a styling rule for a dialog box in the app's user interface. It does not run any code or change how the app starts up.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a profile-pick dialog stage element. It contains only layout properties. There is no code execution, persistence mechanism, or startup modification behavior present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15816

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a styling rule for a heading inside a dialog. It does not affect app startup or persistence.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a profile-pick header heading element. It contains only color and font-size properties. No persistence or startup behavior is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15805

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a CSS layout rule for an image frame in a profile picture picker. It only controls how the element looks on screen.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a profile image frame container, declaring positioning, display, and touch-action properties. No executable code or persistence behavior is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15827

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a CSS style for a resize handle button on an image cropper. It only controls appearance.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a crop resize handle element with border, background, and box-shadow styling. No executable code or persistence mechanism exists in this CSS rule.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15878

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a styling rule that removes margins from text in a dialog header. It has no startup or persistence effect.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is part of a CSS selector group for profile-pick header heading and paragraph elements, setting margin to zero. No executable code or persistence mechanism exists here.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15800

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a CSS visual style for the dashed circle inside an image cropper. It only affects appearance.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a crop handle visual indicator, defining position, border, and pointer-events properties. No executable logic or persistence is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15870

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a styling rule for text margins in a dialog. It does not run code or modify startup behavior.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is part of a CSS selector group for profile-pick header heading and paragraph elements. It only sets margin to zero. No persistence or startup modification is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15801

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a layout styling rule for a dialog header. It does not affect app startup or persistence.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a profile-pick header element with flexbox layout properties. No executable code, persistence, or startup modification exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15791

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a styling rule for a dialog box's size and appearance. It does not run code or change startup behavior.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a profile-pick dialog container with width, height, flex, padding, border, and background properties. No persistence or startup behavior is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15778

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a CSS layout rule for the button row in a profile picture picker dialog. It only controls spacing and alignment.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a profile-pick actions container using flexbox layout properties. No code execution or persistence behavior is involved.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15892

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a CSS style for a dimming overlay on top of an image in the profile picker. It only controls visual appearance.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a semi-transparent overlay scrim, defining absolute positioning and a background color. No persistence or executable code is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15843

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a CSS style for the circular crop box in the profile picture picker. It only controls how the cropping circle looks.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for the circular crop selection box, defining position, border, border-radius, cursor, and box-shadow properties. No executable code or persistence mechanism exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15850

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a CSS style controlling how an image is sized inside the profile picture picker. It only affects layout.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS descendant selector for an image element inside the profile-pick frame, setting display and max-dimensions. No executable code or persistence is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15836

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a styling rule for a dark overlay behind a dialog. It does not affect app startup or persistence.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a profile-pick backdrop overlay with fixed positioning and background properties. No executable code, persistence, or startup modification exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15767

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This is a styling rule for descriptive text in a dialog header. It does not run code or modify startup behavior.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The flagged line is a CSS class selector for a profile-pick header paragraph element with margin and font-size properties. No persistence or startup modification behavior is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/styles.css:15810

Related contextual observations

All six advisories target build-tooling dependencies with no production runtime reachability in this Electron desktop app

low risk · medium confidence

All six security warnings are about tools used to build the app, not the app itself. Since this is a desktop program that runs locally and does not run a website, the issues do not reach people who install and use it.

Technical assessment

The six flagged advisories correspond to known vulnerabilities in development and build tooling (such as bundler dev-server packages) declared in the lockfile. The project is a local-first Electron desktop application that ships a pre-built bundle; the vulnerable code paths are confined to development-time server functionality that is not included in or executed by the production runtime. The scanner removed specific package details, so exact version confirmation against each advisory could not be performed from the supplied source context alone, but the project's architecture and dependency profile indicate no production runtime exposure. The esbuild override to 0.28.1 in package.json suggests the developer is already managing build-tool versions.

Impact: low · Exploitability: unlikely

Developer action: Run a dependency update pass on build tooling to clear all advisories and keep the development environment secure.

Sources:

All candidates are CSS styling rules with no executable behavior

low risk · high confidence

Every flagged item is a visual styling rule for a dialog box in the app's interface. Stylesheets only control appearance and layout and cannot run programs, save data, or change how the app starts.

Technical assessment

All eight candidates are in a production CSS file and correspond to class selectors for a profile-pick dialog UI component. The surrounding source context shows only standard CSS properties such as position, display, flex, padding, border, color, background, and font-size. CSS cannot perform persistence, startup modification, code execution, or network calls. The scanner rule produced false positives by matching selector names in a static stylesheet.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity