TavernKeeper Scan Report
l1kiru/SillyTavern-LorebookAtlas
Commit 7afe0a4 Reviewed
No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger 0 material 7 low
What this review found
No material or immediate-danger item was identified.
Deterministic technical evidence (7)
-
JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-content· Execution scope: test-documentation-dataSource: test/filenames.test.js:9
-
JavaScript analysis reported javascript.xray.short-identifiers · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-content· Execution scope: test-documentation-dataSource: test/manifest.test.js:1
-
JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-content· Execution scope: test-documentation-dataSource: test/lists.test.js:125
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/test.yml:11
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/test.yml:11
-
zizmor reported excessive-permissions · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/test.yml:8-18
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automationSource: .github/workflows/test.yml:12
Coverage and limitations
JavaScript coverage
Tools
- inventory 0.1.0 — completed
- tavernkeeper-static 5 — completed
- gitleaks 8.30.1 — completed
- opengrep 1.26.0 — completed
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1 — completed
- osv-scanner 2.4.0 — not-applicable
- zizmor 1.28.0 — completed
- malcontent 1.25.7 — not-applicable
Limitations
- This advisory review cannot prove the absence of unknown behavior.