TavernKeeper Scan Report
twitter/twemoji
Commit bad3bce Reviewed
No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger 0 material 30 low
What this review found
No material or immediate-danger item was identified.
Deterministic technical evidence (30)
-
JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-tooling· Execution scope: tooling-onlySource: scripts/utils.js:34
-
Dependency advisory GHSA-2g4f-4pwh-qvx6:pkg:cad7e9fb17eb5405be0d1fe2 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-v6h2-p8h4-qcjw:pkg:954583494f7b71625ae8e6ee applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
JavaScript analysis reported javascript.xray.obfuscated-code · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-content· Execution scope: test-documentation-dataSource: src/test/test.js:1
-
Dependency advisory GHSA-mh99-v99m-4gvg:pkg:30da7db405d2e49715cb0ed6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-f8q6-p94x-37v3:pkg:867add7bb9bab6e9895407db applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-content· Execution scope: test-documentation-dataSource: src/test/test.js:1
-
Dependency advisory GHSA-6rw7-vpxm-498p:pkg:0c9bcbbe992a5f1cf2ecf8d6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-p8p7-x288-28g6:pkg:f498895dfeec349e91e305f9 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-w5hq-g745-h8pq:pkg:49d6ddac6a71fb42a3f1a09d applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-hrpp-h998-j3pp:pkg:84deddaa1c5f27b2029349c3 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-fjxv-7rqg-78g4:pkg:6c89c9914b40635e432f1415 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-3ppc-4f35-3m26:pkg:2bf515c0923623db447da2b6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-xvch-5gv4-984h:pkg:01fee4d7faf3fb21b68dbb29 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-7r86-cg39-jmmj:pkg:46587393f7992d1314231deb applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-72xf-g2v4-qvf3:pkg:49c2ec50c11df2c4278b7a4a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-w7jw-789q-3m8p:pkg:16ec289071eeaa1d35511ec9 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-896r-f27r-55mw:pkg:dc62eb0daa24584c8443df50 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-jmr9-qjv8-65gv:pkg:6552b663ea1c29f8d95f9752 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:c6056f5a45897dd10bfacade applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-content· Execution scope: test-documentation-dataSource: src/test/test.js:613
-
Dependency advisory GHSA-3xgq-45jj-v275:pkg:e830bbdbb0dcffffb66f6af5 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-f886-m6hf-6m8v:pkg:db05cad6d25aec0390d39a8c applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-23c5-xmqv-rm74:pkg:0a7bf6a56749ce1808ad443c applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
JavaScript analysis reported javascript.xray.obfuscated-code · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-tooling· Execution scope: tooling-onlySource: scripts/build.js:1
-
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:567c541f015fe4079ca9b17e applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-hmw2-7cc7-3qxx:pkg:b55f5aef11b0369cc46f988a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-vh95-rmgr-6w4m:pkg:c3cf42767ec5124123a5f25a applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-395f-4hp3-45gv:pkg:726b56d7f001ed2589ee915f applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
-
Dependency advisory GHSA-c2qf-rxjj-qqgw:pkg:ab65b7005a72c477b6792a72 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason:
osv-structured-advisory· Execution scope: unknownSource: yarn.lock
Coverage and limitations
JavaScript coverage
Unresolved JavaScript stages
index.d.ts— raw-ast / parsesrc/test/test.js— derived-ast / parsesrc/test/test.js— literal-decode / derivative-limitsrc/test/test.js— normalize / derivative-limitsrc/test/test.js— normalize / unsupported
Tools
- inventory 0.1.0 — completed
- tavernkeeper-static 5 — completed
- gitleaks 8.30.1 — completed
- opengrep 1.26.0 — completed
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1 — completed
- osv-scanner 2.4.0 — completed
- zizmor 1.28.0 — not-applicable
- malcontent 1.25.7 — completed
Limitations
- This advisory review cannot prove the absence of unknown behavior.
- JavaScript analysis was incomplete, so this first-filter scan supports no clean conclusion about unobserved behavior.