TavernKeeper Scan Report

patcireamo/ChungusHub

Commit feb892d Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 44 low

What this review found

No material or immediate-danger item was identified.

Deterministic technical evidence (40)
  • Dependency advisory GHSA-vxr8-fq34-vvx9:pkg:8a3c012a263ab8156620fb0e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/ci.yml:32

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:128

  • zizmor reported template-injection · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:81

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:a9b17cadf83e3a5de547592b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-rp9w-3fw7-7cwq:pkg:4e16d185c39b16c1f350ca4f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-xwg4-73v4-xw9w:pkg:b0abe8c9840bfaafb5747f78 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:d0433ccd51b55fc561da06bf applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-76mc-f452-cxcm:pkg:d0a18325b0cdabed3f35b2c7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-hgv7-v322-mmgr:pkg:857cc203fb4acdf79b8e7afa applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-r47g-fvhr-h676:pkg:642ceee0c4b2cbc4a2e1b121 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-29g2-3rmr-qm68:pkg:0d943943a3e65d55c4ec32e3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported template-injection · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:86

  • Dependency advisory GHSA-c2j3-45gr-mqc4:pkg:42053cd722737fc33c013501 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported artipacked · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:45-49

  • Dependency advisory GHSA-cmwh-pvxp-8882:pkg:6965d223b6bd576889c01d10 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:50

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:006e2a19c763cc0fc17b9679 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-9rmh-mm8f-r9h6:pkg:5d32cd47aeaee1205cf18fc6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:109

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:80dc2988b9d15a40674cea67 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/ci.yml:28

  • Dependency advisory GHSA-wqjv-9729-c5q2:pkg:6699abfbebd5d07abddaa45e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-6g55-p6wh-862q:pkg:be20184562ed7ac60b9bb3c5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-866w-xmhq-wj7x:pkg:d613be3ade05d602f01bb313 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-55q2-fjhq-7xh7:pkg:8332ecd5207902f58f4decb3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-hpcv-96wg-7vj8:pkg:bc90a6f657d85810cfd9cd0b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:45

  • Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:7eb19f2c295342271bbc2245 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:309438d8c981844c76003c01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:b37ba44174078c9afc2349cb applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-77vg-94rm-hx3p:pkg:91c6e2ad95c2c69b9ed18581 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-rcqx-6q8c-2c42:pkg:6c059b35236f63805cd31009 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-f3cj-j4f6-wq85:pkg:e3a54c277ee81743d557b6f7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:92

  • Dependency advisory GHSA-pr6f-5x2q-rwfp:pkg:1d431e95b842ca17fabc7022 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • Dependency advisory GHSA-x4vx-rjvf-j5p4:pkg:f9e26ced39b613e63f6a02d9 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported artipacked · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/ci.yml:28-31

  • Dependency advisory GHSA-gvmj-g25r-r7wr:pkg:2163f78fab2fec7de8db16b4 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: bun.lock

  • zizmor reported cache-poisoning · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/release.yml:50

Contextual expected matches (3)

OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline

Expected behavior · high confidence

The README shows the standard official command for installing Bun, the runtime the project needs. This is documentation for users to run manually, not automated behavior by the application.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.

Contextual assessment: The matched lines are in a README markdown file inside a fenced shell code block under a Requirements heading. The command is the official Bun installer, shown to users as a prerequisite setup step. No executable code in the supplied artifact performs this pipeline; it is documentation instructing users to install the Bun runtime using its official method.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.download-and-execute.shell-pipeline
File role
documentation
Source
README.md:136-137

OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline

Expected behavior · high confidence

The flagged line is a help-page instruction telling people how to install Bun, the supporting software this app needs when run from source. It uses Bun's own standard one-line installer, plainly displayed, pointed at Bun's official site, with no hidden steps. The help page does not download or run anything by itself.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.

Contextual assessment: The match is inside a fenced code block in an installation guide, in a documentation file that executes nothing itself. The flagged line is the Bun runtime vendor's canonical one-line installer for Linux/macOS, shown to readers as the way to obtain the prerequisite the same document and the project README explicitly name. The download destination is the vendor's official install domain, matching the vendor link referenced in the same section, with no project-controlled intermediary, no obfuscation, and no execution triggered by the project. Pipe-to-shell install is a generic supply-chain consideration of the vendor's own distribution method, not a data flow this project introduced or concealed.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.download-and-execute.shell-pipeline
File role
documentation
Source
docs/installation.mdx:28-29

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The script adjusts its own search path while running so it can find the Bun tool. It does not change any system startup files or set up anything that persists after it closes. This is a normal convenience for a development launcher.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification. The match applies to this repository.

Contextual assessment: The scanner matched a comment on line 18 that references ~/.zshrc. The actual code on lines 20-22 only prepends a known install directory to PATH within the current process if bun is not already found, a standard fallback for non-interactive Finder launches. No startup file is created, modified, or appended to. The PATH change is process-local and does not persist after the dev launcher exits. There is no cron entry, launchd plist, login hook, or other persistence mechanism anywhere in the supplied script.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
dev.sh:18

Related contextual observations

Windows prerequisite block uses the same vendor install pattern

low risk · high confidence

The Windows version of the same help step uses the software maker's own one-line installer too. It is the same kind of plainly shown instruction, not a hidden action by the app.

Technical assessment

The Windows code block in the same prerequisites section shows the runtime vendor's official PowerShell install command, the same download-and-execute shape as the flagged Unix line. It targets the same official vendor domain, is fully visible to readers, and serves the same stated purpose of installing the declared prerequisite. It was not separately flagged but belongs to the same pattern class and merits the same conclusion.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity