No material or immediate-danger item was identified.
Dependency advisory GHSA-fjxv-7rqg-78g4:pkg:6c89c9914b40635e432f1415 applies
Minor caution · high confidence
This finding points to an outdated version of form-data, but it is only used during development, not when the emoji library runs in your browser. No one can exploit this while using Twemoji.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fjxv-7rqg-78g4:pkg:6c89c9914b40635e432f1415 to a dependency declared by this repository.
Contextual assessment: form-data@2.3.3 appears as a transitive dependency of build/development tools (likely phantomjs-prebuilt). The Twemoji library does not use form-data at runtime; it is only present in the development build process. No runtime reachability to this vulnerable version is demonstrated in the shipped code.
Impact: none · Exploitability: unlikely
Developer action: Update form-data to a non-vulnerable version (e.g., 2.5.1 or later) in the lockfile by upgrading the parent dependency.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fjxv-7rqg-78g4:pkg:6c89c9914b40635e432f1415
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-3ppc-4f35-3m26:pkg:2bf515c0923623db447da2b6 applies
Minor caution · high confidence
An old version of minimatch is present in the development tools, but it is not used in the emoji functions you call in your web page. There is no danger for Twemoji users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26:pkg:2bf515c0923623db447da2b6 to a dependency declared by this repository.
Contextual assessment: minimatch@3.0.4 is a transitive dependency of npm-run-all, a build-time script runner. The vulnerable ReDoS (GHSA-3ppc-4f35-3m26) affects pattern matching on uncontrolled input, but the Twemoji runtime never exposes minimatch to user input. No runtime reachability is demonstrated.
Impact: none · Exploitability: unlikely
Developer action: Update minimatch to version 3.1.2 or later by upgrading npm-run-all or replacing it with a maintained alternative.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26:pkg:2bf515c0923623db447da2b6
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-xvch-5gv4-984h:pkg:01fee4d7faf3fb21b68dbb29 applies
Minor caution · high confidence
The old minimist version is used only when building the emoji library, not when you use it on your website. It cannot be exploited by an attacker.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvch-5gv4-984h:pkg:01fee4d7faf3fb21b68dbb29 to a dependency declared by this repository.
Contextual assessment: minimist@0.0.8 is a dependency of mkdirp, which is used during the build process only. The vulnerability (GHSA-xvch-5gv4-984h) requires an attacker to control command-line arguments, which is impossible in the shipped client-side library. No runtime exposure.
Impact: none · Exploitability: unlikely
Developer action: Update minimist to 1.2.6 or later by upgrading mkdirp or replacing it with a modern alternative.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvch-5gv4-984h:pkg:01fee4d7faf3fb21b68dbb29
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-7r86-cg39-jmmj:pkg:46587393f7992d1314231deb applies
Minor caution · high confidence
This is another advisory for the same minimatch version. As with the earlier one, it only affects the build tools, not the emoji library itself.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj:pkg:46587393f7992d1314231deb to a dependency declared by this repository.
Contextual assessment: minimatch@3.0.4 is also flagged by a second advisory (GHSA-7r86-cg39-jmmj) for ReDoS. Same rationale as the earlier minimatch finding: the dependency is build-time only and not reachable at runtime.
Impact: none · Exploitability: unlikely
Developer action: Same as the minimatch update recommendation: update to version 3.1.2 or later.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj:pkg:46587393f7992d1314231deb
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-72xf-g2v4-qvf3:pkg:49c2ec50c11df2c4278b7a4a applies
Minor caution · high confidence
An old tough-cookie version appears in the test tools, but it is not part of the code that runs on your website. There is no security impact for users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-72xf-g2v4-qvf3:pkg:49c2ec50c11df2c4278b7a4a to a dependency declared by this repository.
Contextual assessment: tough-cookie@2.4.3 is a dependency of phantomjs-prebuilt, a headless browser used only for testing. It is never shipped to end users or used in the Twemoji runtime. The medium-severity advisory (GHSA-72xf-g2v4-qvf3) relates to cookie parsing, which cannot be triggered in production.
Impact: none · Exploitability: unlikely
Developer action: Update tough-cookie to version 2.5.0 or later by replacing phantomjs-prebuilt with a modern testing tool.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-72xf-g2v4-qvf3:pkg:49c2ec50c11df2c4278b7a4a
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-w7jw-789q-3m8p:pkg:16ec289071eeaa1d35511ec9 applies
Minor caution · high confidence
shell-quote is used only in development scripts, not in the emoji parsing you use in your web page. It cannot be exploited by visitors to your site.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-w7jw-789q-3m8p:pkg:16ec289071eeaa1d35511ec9 to a dependency declared by this repository.
Contextual assessment: shell-quote@1.6.1 is a transitive dependency of npm-run-all, used during development for shell command parsing. The critical advisory (GHSA-w7jw-789q-3m8p) allows command injection on attacker-controlled input, but no data flow from untrusted users reaches this dependency in the Twemoji build process. Runtime reachability is not demonstrated.
Impact: none · Exploitability: unlikely
Developer action: Update shell-quote to version 1.7.3 or later by upgrading npm-run-all or replacing it with a safer alternative.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-w7jw-789q-3m8p:pkg:16ec289071eeaa1d35511ec9
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-896r-f27r-55mw:pkg:dc62eb0daa24584c8443df50 applies
Minor caution · high confidence
json-schema appears in the development tools for building the library. It is not part of the emoji code that runs in your browser, so it poses no risk.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-896r-f27r-55mw:pkg:dc62eb0daa24584c8443df50 to a dependency declared by this repository.
Contextual assessment: json-schema@0.2.3 is a dependency of jsprim, which is used by the phantomjs-prebuilt tool during development. The critical advisory (GHSA-896r-f27r-55mw) relates to prototype pollution, but this code is never executed in the Twemoji runtime or exposed to user input.
Impact: none · Exploitability: unlikely
Developer action: Update json-schema to version 0.4.0 or later by replacing phantomjs-prebuilt with a maintained alternative.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-896r-f27r-55mw:pkg:dc62eb0daa24584c8443df50
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:c6056f5a45897dd10bfacade applies
Minor caution · high confidence
brace-expansion is part of the build tools, not the emoji library. Users are not affected by this vulnerability.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp:pkg:c6056f5a45897dd10bfacade to a dependency declared by this repository.
Contextual assessment: brace-expansion@1.1.11 is a dependency of minimatch, which is used by npm-run-all in the build process. The high-severity advisory (GHSA-3jxr-9vmj-r5cp) indicates a potential ReDoS, but no attacker-controlled input reaches this code in production. Runtime exposure is not demonstrated.
Impact: none · Exploitability: unlikely
Developer action: Update brace-expansion to version 1.1.13 or later by upgrading minimatch or its parent dependency.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp:pkg:c6056f5a45897dd10bfacade
- File role
- production
- Source
- yarn.lock
Expected scanner matches (21)
JavaScript analysis reported javascript.xray.unsafe-command
Expected behavior · high confidence
This code runs a secure command during the build process to create a hash for emoji image files. It does not run when someone visits a website using Twemoji, so there is no risk to users.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-command in this repository.
Contextual assessment: The flagged code at line 34 uses child_process.spawnSync to invoke openssl for generating a SHA-384 integrity hash of a given filename. This is a build-time utility function (getIntegrityHash) used solely by the project's tooling to produce Subresource Integrity (SRI) hash strings for CDN assets, as evidenced by the README's CDN snippet. The command arguments are fixed (algorithm 'sha384', '-binary', user-provided filename). The filename is supplied by the build process, not by untrusted runtime input. Since this code is not shipped or executed in the browser runtime, it does not present a security concern for end users of the Twemoji library. The scanner signal 'unsafe-command' is a static indicator of process spawning, not a vulnerability.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.unsafe-command
- File role
- tooling
- Source
- scripts/utils.js:34
Dependency advisory GHSA-2g4f-4pwh-qvx6:pkg:cad7e9fb17eb5405be0d1fe2 applies
Expected behavior · high confidence
This vulnerable package is only used during development and is not part of the emoji library you would install or use. It poses no risk to users of Twemoji.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6:pkg:cad7e9fb17eb5405be0d1fe2 to a dependency declared by this repository.
Contextual assessment: ajv@6.12.6 is a transitive dependency of phantomjs-prebuilt, a build/test tool. It is not included in the shipped Twemoji runtime library. No attacker-controlled data reaches ajv in the user-facing deliverable. The prototype pollution advisory (GHSA-2g4f-4pwh-qvx6) has no runtime reachability in this project.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2g4f-4pwh-qvx6:pkg:cad7e9fb17eb5405be0d1fe2
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-v6h2-p8h4-qcjw:pkg:954583494f7b71625ae8e6ee applies
Expected behavior · high confidence
This is a build tool dependency that could cause a slowdown if misused, but it is never exposed to users. No user action can trigger this vulnerability.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw:pkg:954583494f7b71625ae8e6ee to a dependency declared by this repository.
Contextual assessment: brace-expansion@1.1.11 is a transitive dependency used by minimatch in build scripts. It is not part of the shipped Twemoji runtime. The ReDoS vulnerability (GHSA-v6h2-p8h4-qcjw) requires attacker-controlled input to the glob matching, which does not occur in the build context for end users.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6h2-p8h4-qcjw:pkg:954583494f7b71625ae8e6ee
- File role
- production
- Source
- yarn.lock
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · high confidence
This is a test file for the Twemoji emoji library. The 'obfuscated code' warning is a mistake—the code uses normal Unicode symbols for emoji, which is exactly what the library is designed to handle. There's nothing hidden or dangerous here.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The scanner flagged the test file `file` with a high-severity signal for obfuscated code. However, the source code is a legitimate test suite for the Twitter Twemoji emoji library. It contains Unicode escape sequences (e.g., \u2764, \uFE0F, \uFE0E) that are standard representations of emoji characters and variant selectors, used to test the library's parsing functionality. There is no obfuscation, concealed execution, or malicious intent. The signal is a false positive caused by the heuristic matching of Unicode escapes as potentially obfuscated content. The file is a test artifact not shipped to users.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- test
- Source
- src/test/test.js:1
Dependency advisory GHSA-mh99-v99m-4gvg:pkg:30da7db405d2e49715cb0ed6 applies
Expected behavior · high confidence
This vulnerability is in a development-only package. Users of Twemoji are not affected because the code is never executed in their browsers.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg:pkg:30da7db405d2e49715cb0ed6 to a dependency declared by this repository.
Contextual assessment: brace-expansion@1.1.11 is also flagged by a high-severity advisory (GHSA-mh99-v99m-4gvg). Like the previous, it is a build-time transitive dependency only. There is no runtime path for an attacker to supply input to brace-expansion in the shipped Twemoji library.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg:pkg:30da7db405d2e49715cb0ed6
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-f8q6-p94x-37v3:pkg:867add7bb9bab6e9895407db applies
Expected behavior · high confidence
This is a development dependency that helps with file processing during building. It does not affect the final emoji script that runs in your browser.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f8q6-p94x-37v3:pkg:867add7bb9bab6e9895407db to a dependency declared by this repository.
Contextual assessment: minimatch@3.0.4 is a build-time dependency (used by npm-run-all and related scripts). It is not part of the runtime Twemoji bundle. The ReDoS vulnerability (GHSA-f8q6-p94x-37v3) is not exploitable because attacker input does not reach minimatch in the shipped library.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f8q6-p94x-37v3:pkg:867add7bb9bab6e9895407db
- File role
- production
- Source
- yarn.lock
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
This is a test file that uses a small emoji image to check if the library works correctly. The scanner thought the image's standard internet address might be suspicious, but it's just the normal way SVG images are written. There's no security issue here.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The candidate is a test file containing an inline SVG element used for testing emoji rendering in the twemoji library. The SVG includes a standard XML namespace (xmlns) attribute that the scanner flagged as a potential shady link, but this is a legitimate and expected namespace declaration for SVG images. No external URLs, network requests, or data exfiltration are present. The file is a test fixture and does not execute in production contexts.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- test
- Source
- src/test/test.js:1
Dependency advisory GHSA-6rw7-vpxm-498p:pkg:0c9bcbbe992a5f1cf2ecf8d6 applies
Expected behavior · high confidence
This vulnerable package is only used during the build process and never ships with the emoji library. End users have no exposure.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6rw7-vpxm-498p:pkg:0c9bcbbe992a5f1cf2ecf8d6 to a dependency declared by this repository.
Contextual assessment: qs@6.5.2 is a transitive dependency of request, which is a dependency of phantomjs-prebuilt. It is a build-time only dependency. The prototype pollution advisory (GHSA-6rw7-vpxm-498p) is not reachable from user input in the shipped Twemoji code.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6rw7-vpxm-498p:pkg:0c9bcbbe992a5f1cf2ecf8d6
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-p8p7-x288-28g6:pkg:f498895dfeec349e91e305f9 applies
Expected behavior · high confidence
This is an old HTTP library used during development. It is not included in the Twemoji script that users load.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-p8p7-x288-28g6:pkg:f498895dfeec349e91e305f9 to a dependency declared by this repository.
Contextual assessment: request@2.88.0 is an HTTP client used by phantomjs-prebuilt for testing and downloading. It is not part of the shipped Twemoji runtime. The advisory (GHSA-p8p7-x288-28g6) concerns server-side request forgery and credential exposure, which are irrelevant in this build-only context.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-p8p7-x288-28g6:pkg:f498895dfeec349e91e305f9
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-w5hq-g745-h8pq:pkg:49d6ddac6a71fb42a3f1a09d applies
Expected behavior · high confidence
This is a UUID generation library only used during the development build. It does not affect the final emoji library delivered to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-w5hq-g745-h8pq:pkg:49d6ddac6a71fb42a3f1a09d to a dependency declared by this repository.
Contextual assessment: uuid@3.3.2 is a transitive dependency of request in the build dependency tree. It is not shipped with the Twemoji runtime. The advisory (GHSA-w5hq-g745-h8pq) regarding insecure randomness has no impact because the package is not exposed to user input or used for any security-sensitive operation in this context.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-w5hq-g745-h8pq:pkg:49d6ddac6a71fb42a3f1a09d
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-hrpp-h998-j3pp:pkg:84deddaa1c5f27b2029349c3 applies
Expected behavior · high confidence
Same as before – this vulnerable package stays behind the scenes during development and never reaches users of the Twemoji emoji tool.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hrpp-h998-j3pp:pkg:84deddaa1c5f27b2029349c3 to a dependency declared by this repository.
Contextual assessment: qs@6.5.2 is flagged again in a high-severity advisory (GHSA-hrpp-h998-j3pp) related to prototype pollution. As previously assessed, this is a build-time only transitive dependency. No attacker-controlled input reaches qs in the shipped Twemoji library.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hrpp-h998-j3pp:pkg:84deddaa1c5f27b2029349c3
- File role
- production
- Source
- yarn.lock
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
This is a test that checks if the emoji library works inside an XHTML iframe. The link it uses is just a small fake webpage made of text, not a real external website. It's completely normal for tests to do this.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: Line 613 in the test file sets an iframe's src to a hardcoded data URI containing a valid XHTML document with a heart emoji. This is a standard test setup to verify that twemoji.parse correctly handles XHTML content within iframes. The data URI is static, well-formed, and has no attacker-controlled input. The signal 'shady-link' from JS-X-Ray is a false positive in this context; the URI is required for the test and poses no security risk.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- test
- Source
- src/test/test.js:613
Dependency advisory GHSA-3xgq-45jj-v275:pkg:e830bbdbb0dcffffb66f6af5 applies
Expected behavior · high confidence
This is a software library that helps build the emoji project, but it's not used when you actually run the emoji code in your browser. So there's no security risk for people using the emoji tool.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3xgq-45jj-v275:pkg:e830bbdbb0dcffffb66f6af5 to a dependency declared by this repository.
Contextual assessment: Cross-spawn at version 6.0.5 is a build-time transitive dependency used by npm-run-all and other development tools. It is not shipped in the runtime twemoji.min.js bundle and has no execution path in the user's browser when using the emoji library. No evidence of runtime reachability.
Impact: none · Exploitability: unlikely
Developer action: Consider updating the dependency as a routine maintenance step, but this does not affect shipped users.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3xgq-45jj-v275:pkg:e830bbdbb0dcffffb66f6af5
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-f886-m6hf-6m8v:pkg:db05cad6d25aec0390d39a8c applies
Expected behavior · high confidence
This is part of the build tools for creating the emoji project, not something that runs when you use the emoji on a website. No danger to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v:pkg:db05cad6d25aec0390d39a8c to a dependency declared by this repository.
Contextual assessment: Brace-expansion at version 1.1.11 is a dependency of minimatch, which is used by build-time tools like npm-run-all. It is not part of the shipped twemoji runtime and has no attacker-controlled input path in the end-user environment.
Impact: none · Exploitability: unlikely
Developer action: Update to a non-vulnerable version as a housekeeping step.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v:pkg:db05cad6d25aec0390d39a8c
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-23c5-xmqv-rm74:pkg:0a7bf6a56749ce1808ad443c applies
Expected behavior · high confidence
This is a helper for building the project, not something that runs in your browser when you view emojis. No risk.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74:pkg:0a7bf6a56749ce1808ad443c to a dependency declared by this repository.
Contextual assessment: Minimatch at version 3.0.4 is a build-time dependency of npm-run-all and other development scripts. It is not included in the client-side twemoji distribution and cannot be reached by user input in the deployed library.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74:pkg:0a7bf6a56749ce1808ad443c
- File role
- production
- Source
- yarn.lock
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · high confidence
This is a build script that creates a JavaScript file from a function. It is not hiding malicious code, it is just how this project packages its emoji library. The build script is a normal part of development and does not pose any risk.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The source file file is a build-time tooling script for the twitter/twemoji project. It generates the dist/twemoji.js bundle by serializing an inline function via .toString() and performing string replacements to inject the emoji regex and version. This is a standard code-generation pattern, not obfuscation. The scanner's 'obfuscated-code' signal is a false positive produced by JS-X-Ray's heuristic matching against runtime code construction. The script has no hidden execution, no network calls beyond local file I/O, and no user-configurable input. It runs only during the build step and is never shipped to end users.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- tooling
- Source
- scripts/build.js:1
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:567c541f015fe4079ca9b17e applies
Expected behavior · high confidence
This is a duplicate notice for the same build tool dependency. Still not used by the emoji code that runs on your site.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895:pkg:567c541f015fe4079ca9b17e to a dependency declared by this repository.
Contextual assessment: Brace-expansion at version 1.1.11 (duplicate advisory) is a build-time transitive dependency with no runtime exposure in the shipped twemoji assets. No data flow to users.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895:pkg:567c541f015fe4079ca9b17e
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-hmw2-7cc7-3qxx:pkg:b55f5aef11b0369cc46f988a applies
Expected behavior · high confidence
This is used during development to test the emoji images, not in the final code that browsers run. No security concern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hmw2-7cc7-3qxx:pkg:b55f5aef11b0369cc46f988a to a dependency declared by this repository.
Contextual assessment: Form-data at version 2.3.3 is a dependency of request and phantomjs-prebuilt, which are used only for build-time testing and rendering. It is not part of the client-side twemoji library and has no exposed attack surface for users.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hmw2-7cc7-3qxx:pkg:b55f5aef11b0369cc46f988a
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-vh95-rmgr-6w4m:pkg:c3cf42767ec5124123a5f25a applies
Expected behavior · high confidence
This is a small tool used only when building the project, not when using the emoji library. No risk.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-vh95-rmgr-6w4m:pkg:c3cf42767ec5124123a5f25a to a dependency declared by this repository.
Contextual assessment: Minimist at version 0.0.8 is a CLI argument parser dependency of mkdirp, which is used only during build. It is not executed in the browser and has no reachable attack surface in the final product.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-vh95-rmgr-6w4m:pkg:c3cf42767ec5124123a5f25a
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-395f-4hp3-45gv:pkg:726b56d7f001ed2589ee915f applies
Expected behavior · high confidence
This is a command-line tool used only during development. It doesn't affect the emoji code that runs on websites.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-395f-4hp3-45gv:pkg:726b56d7f001ed2589ee915f to a dependency declared by this repository.
Contextual assessment: Shell-quote at version 1.6.1 is a build-time dependency used by npm-run-all and other development scripts. It is not included in the twemoji runtime distribution and cannot be triggered by end users.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-395f-4hp3-45gv:pkg:726b56d7f001ed2589ee915f
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-c2qf-rxjj-qqgw:pkg:ab65b7005a72c477b6792a72 applies
Expected behavior · high confidence
This is a utility for comparing software versions, used only during the build process. Not a risk for emoji users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2qf-rxjj-qqgw:pkg:ab65b7005a72c477b6792a72 to a dependency declared by this repository.
Contextual assessment: Semver at version 5.7.0 is a version comparison tool used by many build-time packages. It is not part of the shipped twemoji.min.js and has no execution context in the browser. No evidence of real-world exposure.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2qf-rxjj-qqgw:pkg:ab65b7005a72c477b6792a72
- File role
- production
- Source
- yarn.lock