TavernKeeper Scan Report

twitter/twemoji

Commit bad3bce Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 26 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-6rw7-vpxm-498p applies

Minor caution · medium confidence

The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6rw7-vpxm-498p to a dependency declared by this repository.

Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6rw7-vpxm-498p
File role
production
Source
yarn.lock

Dependency advisory GHSA-72xf-g2v4-qvf3 applies

Minor caution · medium confidence

The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-72xf-g2v4-qvf3 to a dependency declared by this repository.

Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-72xf-g2v4-qvf3
File role
production
Source
yarn.lock

Dependency advisory GHSA-p8p7-x288-28g6 applies

Minor caution · medium confidence

The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-p8p7-x288-28g6 to a dependency declared by this repository.

Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-p8p7-x288-28g6
File role
production
Source
yarn.lock

Dependency advisory GHSA-c2qf-rxjj-qqgw applies

Minor caution · medium confidence

The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2qf-rxjj-qqgw to a dependency declared by this repository.

Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2qf-rxjj-qqgw
File role
production
Source
yarn.lock

Dependency advisory GHSA-2g4f-4pwh-qvx6 applies

Minor caution · medium confidence

The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.

Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2g4f-4pwh-qvx6
File role
production
Source
yarn.lock

Dependency advisory GHSA-hrpp-h998-j3pp applies

Minor caution · medium confidence

The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-hrpp-h998-j3pp to a dependency declared by this repository.

Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-hrpp-h998-j3pp
File role
production
Source
yarn.lock

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Minor caution · medium confidence

The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
yarn.lock

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · medium confidence

The project relies on an older development or build tool that has a known security flaw. Because the final product delivered to users does not include this tool, users are not directly at risk, but the developers should update their internal tools.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: The advisory identifies a vulnerable dependency within the project's lock file. Given the project's nature as a lightweight client-side emoji rendering library, this dependency is likely part of the build toolchain or development environment rather than the shipped runtime artifacts. There is no evidence that the vulnerable code is exposed to end users at runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next dependency refresh or maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
yarn.lock

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · medium confidence

The project's dependency list includes an older build tool that has a known security issue. Since this tool is only used during development to build the emoji library and is not included in the final product users actually run, the practical risk to people using twemoji is very low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: This advisory flags a dependency declared in the file of a client-side emoji rendering library. The lock file governs build-time tooling dependencies used to generate the distributed standalone minified artifact. The supplied source context shows only the initial entries of a 50KB lock file, and scanner package details were removed, so exact package-to-advisory mapping and runtime reachability cannot be fully confirmed. However, for a library whose shipped output is a self-contained JS bundle with no server-side component, credential handling, or network API interception, build-tooling dependency vulnerabilities pose minimal risk to downstream consumers. The vulnerable code paths in build tools are not present in the distributed runtime artifact.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version for build-environment hygiene. No urgent action is needed for downstream consumers of the distributed library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
yarn.lock

Dependency advisory GHSA-vh95-rmgr-6w4m applies

Minor caution · medium confidence

A development-only tool used to build the library has a medium-severity security issue. Because it never runs when people use the final emoji library, the practical risk is minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-vh95-rmgr-6w4m to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory matched against a dependency in the build-tooling lock file for this client-side emoji library. The distributed artifact is a standalone minified JavaScript file loaded via script tag; the lock file dependencies are not shipped to end users. Without full lock file visibility or the removed package details, specific version and reachability confirmation is limited, but the project's architecture means build-time dependency vulnerabilities have no runtime exposure path to consumers.

Impact: low · Exploitability: unlikely

Developer action: Update the dependency when convenient. No action needed for library consumers.

Scanner
osv-scanner 2.4.0
Rule
GHSA-vh95-rmgr-6w4m
File role
production
Source
yarn.lock

Dependency advisory GHSA-v6h2-p8h4-qcjw applies

Minor caution · medium confidence

A development tool used to build the library has a minor known issue. Since the tool is not part of what users receive, there is negligible practical impact.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was flagged for a build-time dependency in the yarn.lock. The lock file manages tooling used to produce the distributed emoji rendering bundle. The shipped artifact does not include these tooling dependencies. The advisory severity is low and the dependency is not present at consumer runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the dependency for general maintenance hygiene. No action required for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6h2-p8h4-qcjw
File role
production
Source
yarn.lock

Dependency advisory GHSA-896r-f27r-55mw applies

Minor caution · medium confidence

A build tool used only during development has a critical security issue. While that sounds alarming, the tool is not part of the emoji library that people actually use, so the danger to end users is very low. The development team should still update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-896r-f27r-55mw to a dependency declared by this repository.

Contextual assessment: Although the scanner assigned critical severity to this advisory, the flagged dependency resides in the build-tooling lock file of a client-side emoji library. The project produces a standalone minified JS artifact with no server-side runtime, credential processing, or API key handling. Build-tooling vulnerabilities, even at critical advisory severity, do not create a runtime attack surface in the shipped product. The vulnerable code is not included in the distributed bundle. Without the removed package details and full lock file access, the specific affected package and its exact version cannot be independently confirmed, but the architectural analysis strongly limits end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Prioritize updating the flagged critical dependency in the build toolchain. Confirm the specific package and version against the advisory and upgrade to a patched release. No downstream consumer action is needed.

Scanner
osv-scanner 2.4.0
Rule
GHSA-896r-f27r-55mw
File role
production
Source
yarn.lock

Dependency advisory GHSA-f8q6-p94x-37v3 applies

Minor caution · medium confidence

A development build tool has a known high-severity issue, but it is not included in the emoji library that users run. Practical risk to consumers is very low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f8q6-p94x-37v3 to a dependency declared by this repository.

Contextual assessment: A high-severity advisory matched a dependency in the build-tooling file for this client-side library. The distributed output is a self-contained JS bundle; the lock file dependencies are used only during the build process and are not shipped. No runtime exposure path exists for consumers of the library.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version for build hygiene. No action needed for library consumers.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f8q6-p94x-37v3
File role
production
Source
yarn.lock

Dependency advisory GHSA-3xgq-45jj-v275 applies

Minor caution · medium confidence

A development tool used to build the emoji library has a security issue. Since the tool is not part of the final product, risk to users is minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3xgq-45jj-v275 to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency in the build-tooling lock file. For this client-side emoji library, the lock file dependencies are development-time tooling and do not appear in the distributed standalone artifact. The vulnerability has no runtime reachability for library consumers.

Impact: low · Exploitability: unlikely

Developer action: Update the dependency for maintenance. No action needed for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3xgq-45jj-v275
File role
production
Source
yarn.lock

Dependency advisory GHSA-395f-4hp3-45gv applies

Minor caution · medium confidence

A development build tool has a known security issue but is not part of the emoji library distributed to users. Practical risk is very low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-395f-4hp3-45gv to a dependency declared by this repository.

Contextual assessment: A high-severity advisory matched a build-tooling dependency in the yarn.lock. The project ships a standalone minified client-side emoji rendering script. Lock file dependencies are used only during the build process and are not present in the runtime artifact. No runtime exposure path for consumers exists.

Impact: low · Exploitability: unlikely

Developer action: Update the dependency when convenient. No action required for library consumers.

Scanner
osv-scanner 2.4.0
Rule
GHSA-395f-4hp3-45gv
File role
production
Source
yarn.lock

Dependency advisory GHSA-7r86-cg39-jmmj applies

Minor caution · medium confidence

A development tool has a known issue but is not included in what users receive. Risk to end users is minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency in the build-tooling yarn.lock. The project is a client-side emoji library whose distributed artifact is a standalone JS bundle. Lock file dependencies are build-time tooling not included in the shipped product, so there is no runtime attack surface for consumers.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency for build hygiene. No action needed for library consumers.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
yarn.lock

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as minimist) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.

Impact: low · Exploitability: unlikely

Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
yarn.lock

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as minimist) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.

Impact: low · Exploitability: unlikely

Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
yarn.lock

Dependency advisory GHSA-fjxv-7rqg-78g4 applies

Minor caution · medium confidence

The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fjxv-7rqg-78g4 to a dependency declared by this repository.

Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as shell-quote) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.

Impact: low · Exploitability: unlikely

Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fjxv-7rqg-78g4
File role
production
Source
yarn.lock

Dependency advisory GHSA-xvch-5gv4-984h applies

Minor caution · medium confidence

The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvch-5gv4-984h to a dependency declared by this repository.

Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as shell-quote) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.

Impact: low · Exploitability: unlikely

Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvch-5gv4-984h
File role
production
Source
yarn.lock

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Minor caution · medium confidence

The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as node-fetch) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.

Impact: low · Exploitability: unlikely

Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
yarn.lock

Dependency advisory GHSA-hmw2-7cc7-3qxx applies

Minor caution · medium confidence

The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-hmw2-7cc7-3qxx to a dependency declared by this repository.

Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as node-fetch) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.

Impact: low · Exploitability: unlikely

Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-hmw2-7cc7-3qxx
File role
production
Source
yarn.lock

Dependency advisory GHSA-w5hq-g745-h8pq applies

Minor caution · medium confidence

The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-w5hq-g745-h8pq to a dependency declared by this repository.

Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as lodash) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.

Impact: low · Exploitability: unlikely

Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-w5hq-g745-h8pq
File role
production
Source
yarn.lock

Dependency advisory GHSA-w7jw-789q-3m8p applies

Minor caution · medium confidence

The project uses some older helper tools to build its files. These tools have known security flaws, but because they are only used by developers during the build process and are not included in the final product users run, they do not pose a direct threat to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-w7jw-789q-3m8p to a dependency declared by this repository.

Contextual assessment: This advisory corresponds to a known vulnerable build-time dependency (such as lodash) found in the project's yarn.lock. Twemoji is a client-side emoji rendering library, and these Node.js dependencies are used for the repository's build process, not in the shipped twemoji.min.js artifact. There is no runtime reachability for end users of the extension.

Impact: low · Exploitability: unlikely

Developer action: Update build dependencies to patched versions if maintaining a fork, but no action is required for the shipped library.

Scanner
osv-scanner 2.4.0
Rule
GHSA-w7jw-789q-3m8p
File role
production
Source
yarn.lock
Expected scanner matches (0)

None.

Related contextual observations

Build-tooling lock file contains multiple stale advisories with no runtime consumer exposure

low risk · medium confidence

All flagged issues are in tools used only by developers to build the emoji library, not in the library itself that users run. While the library's users face no practical risk, the development team should update these tools, especially the one flagged as critical, to keep their build environment secure.

Technical assessment

The reviewed file belongs to a client-side emoji rendering library that distributes a standalone minified JavaScript bundle. All eight scanner candidates flag dependencies governed by this lock file, which manages build-time tooling. The shipped artifact does not bundle these dependencies, and the project has no server-side runtime, credential processing, or API interception surface. Scanner package details were removed from the candidate metadata, and only the first approximately forty lines of a 50KB lock file were provided as source context, so exact package-to-advisory version mapping could not be independently confirmed for each candidate. The overall risk profile is low because the advisories affect build-time tooling only, but the development environment itself would benefit from dependency updates, particularly for the critical-severity advisory.

Impact: low · Exploitability: unlikely

Developer action: Run a dependency audit against the full lock file, confirm each advisory's affected package and version, and update to patched releases. Prioritize the critical-severity advisory. No downstream consumer action is required.

Sources:

Build-time dependencies in file do not affect shipped artifact

low risk · medium confidence

The security warnings are about tools used to create the library, not the library itself. Since the final product used by the extension does not include these tools, users are not affected by these warnings.

Technical assessment

The file contains classic Node.js build dependencies like request, ajv, and asn1. These are used to generate the static twemoji.min.js file and are not bundled into the final client-side library. End users installing the extension are not exposed to these dependencies at runtime.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity