What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-6rw7-vpxm-498p applies
Minor caution · medium confidence
The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6rw7-vpxm-498p to a dependency declared by this repository.
Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6rw7-vpxm-498p
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-72xf-g2v4-qvf3 applies
Minor caution · medium confidence
The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-72xf-g2v4-qvf3 to a dependency declared by this repository.
Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-72xf-g2v4-qvf3
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-p8p7-x288-28g6 applies
Minor caution · medium confidence
The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-p8p7-x288-28g6 to a dependency declared by this repository.
Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-p8p7-x288-28g6
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-c2qf-rxjj-qqgw applies
Minor caution · medium confidence
The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2qf-rxjj-qqgw to a dependency declared by this repository.
Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2qf-rxjj-qqgw
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-2g4f-4pwh-qvx6 applies
Minor caution · medium confidence
The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.
Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2g4f-4pwh-qvx6
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-hrpp-h998-j3pp applies
Minor caution · medium confidence
The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hrpp-h998-j3pp to a dependency declared by this repository.
Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hrpp-h998-j3pp
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Minor caution · medium confidence
The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · medium confidence
The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
The project's dependency list includes an older build tool that has a known security issue. Since this tool is only used during development to build the emoji library and is not included in the final product users actually run, the practical risk to people using twemoji is very low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: This advisory flags a dependency declared in the file of a client-side emoji rendering library. The lock file governs build-time tooling dependencies used to generate the distributed standalone minified artifact. The supplied source context shows only the initial entries of a 50KB lock file, and scanner package details were removed, so exact package-to-advisory mapping and runtime reachability cannot be fully confirmed. However, for a library whose shipped output is a self-contained JS bundle with no server-side component, credential handling, or network API interception, build-tooling dependency vulnerabilities pose minimal risk to downstream consumers. The vulnerable code paths in build tools are not present in the distributed runtime artifact.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version for build-environment hygiene. No urgent action is needed for downstream consumers of the distributed library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-vh95-rmgr-6w4m applies
Minor caution · medium confidence
A development-only tool used to build the library has a medium-severity security issue. Because it never runs when people use the final emoji library, the practical risk is minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-vh95-rmgr-6w4m to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory matched against a dependency in the build-tooling lock file for this client-side emoji library. The distributed artifact is a standalone minified JavaScript file loaded via script tag; the lock file dependencies are not shipped to end users. Without full lock file visibility or the removed package details, specific version and reachability confirmation is limited, but the project's architecture means build-time dependency vulnerabilities have no runtime exposure path to consumers.
Impact: low · Exploitability: unlikely
Developer action: Update the dependency when convenient. No action needed for library consumers.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-vh95-rmgr-6w4m
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-v6h2-p8h4-qcjw applies
Minor caution · medium confidence
A development tool used to build the library has a minor known issue. Since the tool is not part of what users receive, there is negligible practical impact.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.
Contextual assessment: A low-severity advisory was flagged for a build-time dependency in the yarn.lock. The lock file manages tooling used to produce the distributed emoji rendering bundle. The shipped artifact does not include these tooling dependencies. The advisory severity is low and the dependency is not present at consumer runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the dependency for general maintenance hygiene. No action required for end users.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6h2-p8h4-qcjw
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-896r-f27r-55mw applies
Minor caution · medium confidence
A build tool used only during development has a critical security issue. While that sounds alarming, the tool is not part of the emoji library that people actually use, so the danger to end users is very low. The development team should still update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-896r-f27r-55mw to a dependency declared by this repository.
Contextual assessment: Although the scanner assigned critical severity to this advisory, the flagged dependency resides in the build-tooling lock file of a client-side emoji library. The project produces a standalone minified JS artifact with no server-side runtime, credential processing, or API key handling. Build-tooling vulnerabilities, even at critical advisory severity, do not create a runtime attack surface in the shipped product. The vulnerable code is not included in the distributed bundle. Without the removed package details and full lock file access, the specific affected package and its exact version cannot be independently confirmed, but the architectural analysis strongly limits end-user impact.
Impact: low · Exploitability: unlikely
Developer action: Prioritize updating the flagged critical dependency in the build toolchain. Confirm the specific package and version against the advisory and upgrade to a patched release. No downstream consumer action is needed.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-896r-f27r-55mw
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-f8q6-p94x-37v3 applies
Minor caution · medium confidence
A development build tool has a known high-severity issue, but it is not included in the emoji library that users run. Practical risk to consumers is very low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f8q6-p94x-37v3 to a dependency declared by this repository.
Contextual assessment: A high-severity advisory matched a dependency in the build-tooling file for this client-side library. The distributed output is a self-contained JS bundle; the lock file dependencies are used only during the build process and are not shipped. No runtime exposure path exists for consumers of the library.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version for build hygiene. No action needed for library consumers.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f8q6-p94x-37v3
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-3xgq-45jj-v275 applies
Minor caution · medium confidence
A development tool used to build the emoji library has a security issue. Since the tool is not part of the final product, risk to users is minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3xgq-45jj-v275 to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency in the build-tooling lock file. For this client-side emoji library, the lock file dependencies are development-time tooling and do not appear in the distributed standalone artifact. The vulnerability has no runtime reachability for library consumers.
Impact: low · Exploitability: unlikely
Developer action: Update the dependency for maintenance. No action needed for end users.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3xgq-45jj-v275
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-395f-4hp3-45gv applies
Minor caution · medium confidence
A development build tool has a known security issue but is not part of the emoji library distributed to users. Practical risk is very low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-395f-4hp3-45gv to a dependency declared by this repository.
Contextual assessment: A high-severity advisory matched a build-tooling dependency in the yarn.lock. The project ships a standalone minified client-side emoji rendering script. Lock file dependencies are used only during the build process and are not present in the runtime artifact. No runtime exposure path for consumers exists.
Impact: low · Exploitability: unlikely
Developer action: Update the dependency when convenient. No action required for library consumers.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-395f-4hp3-45gv
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-7r86-cg39-jmmj applies
Minor caution · medium confidence
A development tool has a known issue but is not included in what users receive. Risk to end users is minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency in the build-tooling yarn.lock. The project is a client-side emoji library whose distributed artifact is a standalone JS bundle. Lock file dependencies are build-time tooling not included in the shipped product, so there is no runtime attack surface for consumers.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency for build hygiene. No action needed for library consumers.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as minimist) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.
Impact: low · Exploitability: unlikely
Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as minimist) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.
Impact: low · Exploitability: unlikely
Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-fjxv-7rqg-78g4 applies
Minor caution · medium confidence
The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fjxv-7rqg-78g4 to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as shell-quote) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.
Impact: low · Exploitability: unlikely
Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fjxv-7rqg-78g4
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-xvch-5gv4-984h applies
Minor caution · medium confidence
The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvch-5gv4-984h to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as shell-quote) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.
Impact: low · Exploitability: unlikely
Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvch-5gv4-984h
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as node-fetch) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.
Impact: low · Exploitability: unlikely
Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-hmw2-7cc7-3qxx applies
Minor caution · medium confidence
The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hmw2-7cc7-3qxx to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as node-fetch) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.
Impact: low · Exploitability: unlikely
Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hmw2-7cc7-3qxx
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-w5hq-g745-h8pq applies
Minor caution · medium confidence
The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-w5hq-g745-h8pq to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as lodash) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.
Impact: low · Exploitability: unlikely
Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-w5hq-g745-h8pq
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-w7jw-789q-3m8p applies
Minor caution · medium confidence
The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-w7jw-789q-3m8p to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as lodash) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.
Impact: low · Exploitability: unlikely
Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-w7jw-789q-3m8p
- File role
- production
- Source
- yarn.lock
Expected scanner matches (0)
None.