What this review found
Dependency advisory GHSA-v39h-62p7-jpjc applies
Material concern · medium confidence
A tool found that one of the project's packages has a serious known security flaw. It is probably in the build tools rather than the extension itself, but serious issues in build tools can still be a problem and should be fixed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-v39h-62p7-jpjc) against a declared dependency. The project declares only sillytavern-utils-lib as a production dependency; remaining packages are devDependencies for build and test. The high severity warrants attention even if the affected package is likely a transitive build-time dependency, because supply-chain vulnerabilities in build tooling can compromise build integrity. Specific package identity was not provided, limiting precise impact determination.
Impact: medium · Exploitability: unlikely
Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v39h-62p7-jpjc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-q3j6-qgpj-74h6 applies
Material concern · medium confidence
A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed to keep the build process safe.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-q3j6-qgpj-74h6) against a declared dependency. The high severity warrants attention. Without specific package identity, precise runtime versus build-time exposure cannot be confirmed, but the project structure suggests likely build-tooling involvement. High-severity advisories in build tooling can affect build integrity and should be remediated.
Impact: medium · Exploitability: unlikely
Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q3j6-qgpj-74h6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-wf6x-7x77-mvgw applies
Material concern · medium confidence
A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-wf6x-7x77-mvgw) against a declared dependency. The high severity warrants attention. The project structure indicates most dependencies are devDependencies for build and test, but without the specific package identity, runtime exposure cannot be fully ruled out. Remediation is recommended.
Impact: medium · Exploitability: unlikely
Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-wf6x-7x77-mvgw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Material concern · medium confidence
A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-23c5-xmqv-rm74) against a declared dependency. The high severity warrants attention. The project structure suggests likely build-tooling involvement, but specific package identity was not provided, limiting precise impact determination. High-severity advisories should be remediated regardless of dev versus production classification.
Impact: medium · Exploitability: unlikely
Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Material concern · medium confidence
A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-3jxr-9vmj-r5cp) against a declared dependency. The high severity warrants attention. The project structure indicates most dependencies are devDependencies, but without specific package identity, runtime exposure cannot be fully ruled out. Remediation is recommended.
Impact: medium · Exploitability: unlikely
Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v56q-mh7h-f735 applies
Material concern · medium confidence
A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-v56q-mh7h-f735) against a declared dependency. The high severity warrants attention. The project structure suggests likely build-tooling involvement, but specific package identity was not provided. High-severity advisories should be remediated regardless of dev versus production classification.
Impact: medium · Exploitability: unlikely
Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v56q-mh7h-f735
- File role
- production
- Source
- package-lock.json
Minor cautions
Dependency advisory GHSA-v6h2-p8h4-qcjw applies
Minor caution · medium confidence
A tool used during development has a known minor security issue. This does not affect the extension that users actually install and run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.
Contextual assessment: A known low-severity advisory was matched against a dependency declared in the lockfile. The project's only runtime dependency is sillytavern-utils-lib; all other declared dependencies are devDependencies used for building and testing. The built artifact loaded by SillyTavern is dist/index.js, which is not affected by dev-tooling vulnerabilities. Without the specific package name it is not possible to confirm production exposure, but the project structure strongly suggests this is a dev-dependency issue.
Impact: low · Exploitability: unlikely
Developer action: Update devDependencies to their latest patched versions when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6h2-p8h4-qcjw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4x5r-pxfx-6jf8 applies
Minor caution · medium confidence
A development tool has a known minor security issue. The extension users install is not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.
Contextual assessment: A known low-severity advisory was matched against a dependency in the lockfile. The project declares only sillytavern-utils-lib as a runtime dependency; all other packages are devDependencies for build and test tooling. The shipped extension artifact is the webpack bundle, not the dev toolchain. This is most likely a dev-dependency vulnerability with no production impact.
Impact: low · Exploitability: unlikely
Developer action: Update devDependencies to their latest patched versions when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4x5r-pxfx-6jf8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fv7c-fp4j-7gwp applies
Minor caution · medium confidence
A development or build tool has a known security issue rated high, but it is not part of the extension that users install and run. It mainly matters for the developer's own build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.
Contextual assessment: A known high-severity advisory was matched against a dependency in the lockfile. Despite the high scanner severity, the project structure shows only sillytavern-utils-lib as a runtime dependency, with all other packages being devDependencies for build and test. The shipped artifact is the webpack bundle in dist/index.js. High-severity advisories in dev tooling do not directly compromise the runtime extension, though they could affect the build environment if an attacker has access to it.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version. If the advisory affects sillytavern-utils-lib or its transitive production dependencies, prioritize the upgrade.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fv7c-fp4j-7gwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh29-5h37-fv8m applies
Minor caution · medium confidence
A development tool has a known medium security issue. The extension users install is not directly affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.
Contextual assessment: A known medium-severity advisory was matched against a dependency in the lockfile. The project's runtime dependency surface is limited to sillytavern-utils-lib; all other declared packages are devDependencies. The extension ships a webpack bundle, not the dev toolchain. This is most likely a dev-dependency vulnerability with no direct production impact.
Impact: low · Exploitability: unlikely
Developer action: Update devDependencies to their latest patched versions when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh29-5h37-fv8m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qj8w-gfj5-8c6v applies
Minor caution · medium confidence
A development tool has a known medium security issue. The extension users install is not directly affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.
Contextual assessment: A known medium-severity advisory was matched against a dependency in the lockfile. The project declares only sillytavern-utils-lib as a runtime dependency; all other packages are devDependencies. The shipped extension is a webpack bundle. This is most likely a dev-dependency vulnerability with no direct production impact.
Impact: low · Exploitability: unlikely
Developer action: Update devDependencies to their latest patched versions when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qj8w-gfj5-8c6v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5c6j-r48x-rmvq applies
Minor caution · medium confidence
A development or build tool has a known security issue rated high, but it is not part of the extension that users install and run. It mainly matters for the developer's own build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.
Contextual assessment: A known high-severity advisory was matched against a dependency in the lockfile. The project structure shows only sillytavern-utils-lib as a runtime dependency, with all other packages being devDependencies for build and test. The shipped artifact is the webpack bundle. High-severity advisories in dev tooling do not directly compromise the runtime extension, though they could affect the build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version. If the advisory affects sillytavern-utils-lib or its transitive production dependencies, prioritize the upgrade.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5c6j-r48x-rmvq
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2hh-gcrm-f6hx applies
Minor caution · medium confidence
A development or build tool has a known security issue rated high, but it is not part of the extension that users install and run. It mainly matters for the developer's own build environment.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.
Contextual assessment: A known high-severity advisory was matched against a dependency in the lockfile. The project declares only sillytavern-utils-lib as a runtime dependency; all other packages are devDependencies. The shipped extension is a webpack bundle. High-severity advisories in dev tooling do not directly compromise the runtime extension, though they could affect the build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version. If the advisory affects sillytavern-utils-lib or its transitive production dependencies, prioritize the upgrade.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-968p-4wvh-cqc8 applies
Minor caution · medium confidence
A development tool has a known medium security issue. The extension users install is not directly affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-968p-4wvh-cqc8 to a dependency declared by this repository.
Contextual assessment: A known medium-severity advisory was matched against a dependency in the lockfile. The project's runtime dependency surface is limited to sillytavern-utils-lib; all other declared packages are devDependencies. The extension ships a webpack bundle, not the dev toolchain. This is most likely a dev-dependency vulnerability with no direct production impact.
Impact: low · Exploitability: unlikely
Developer action: Update devDependencies to their latest patched versions when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-968p-4wvh-cqc8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2g4f-4pwh-qvx6 applies
Minor caution · medium confidence
A tool found that one of the packages used by this project has a known security issue. It is probably part of the build tools rather than the actual extension users run, so the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-2g4f-4pwh-qvx6) against a declared dependency in the lockfile. The project's only production runtime dependency is sillytavern-utils-lib; all other declared dependencies are devDependencies used for build and test tooling. Without the specific package identity it is not possible to confirm runtime exposure, but the project structure suggests this most likely affects build-time tooling rather than the extension code shipped to users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the affected package and update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2g4f-4pwh-qvx6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-h67p-54hq-rp68 applies
Minor caution · medium confidence
A tool found a medium-level security issue in one of the project's packages. It is likely in the build tools and poses low risk to users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-h67p-54hq-rp68) against a declared dependency. Given the project structure with predominantly devDependencies, this likely affects build or test tooling. Medium-severity issues in build tooling for a hobbyist extension present low practical risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the affected package and update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h67p-54hq-rp68
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7 applies
Minor caution · medium confidence
A security scanner found that one of the tools used to build this extension has a known security issue. Since this is likely a build-time tool rather than something that runs when you use the extension, it probably does not affect end users directly.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory against a declared dependency in the lockfile. The project's runtime dependency surface is limited to sillytavern-utils-lib; the remaining declared dependencies are build-time dev tooling (babel, webpack, jest, sass, typescript). Vulnerabilities in dev-only transitive dependencies do not flow into the built extension artifact shipped to end users. Without the specific package name it is not possible to confirm whether this advisory affects a production or dev-only dependency, but the project structure strongly suggests dev tooling exposure.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner with package details to identify the specific vulnerable package and update it to a fixed version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7r86-cg39-jmmj applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the packages listed in this project's dependency lockfile. This is most likely in a development tool and would not affect people using the finished extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory against a declared dependency in the lockfile. The project declares only one production dependency (sillytavern-utils-lib) with all other packages being dev-only build tooling. Vulnerabilities in dev-only transitive dependencies do not propagate to the built dist/index.js artifact that end users load. The specific package name was not supplied, preventing confirmation of whether this affects a production or dev-only dependency.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific vulnerable package via npm audit and update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8fgc-7cc6-rx7x applies
Minor caution · medium confidence
A security scanner found a low-severity known issue in one of this project's dependencies. This is most likely in a development tool and is unlikely to affect users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity known advisory against a declared dependency in the lockfile. The project's dependency tree is dominated by dev-only build tooling. Low-severity advisories in dev tooling transitive dependencies have minimal practical impact on the shipped extension artifact.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package and update it when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8fgc-7cc6-rx7x
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xvcm-6775-5m9r applies
Minor caution · medium confidence
A security scanner flagged a high-severity vulnerability in a dependency. However, this project uses mostly development tools, so the issue likely affects only the build environment, not the extension that users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity known advisory against a declared dependency in the lockfile. Despite the scanner severity, the project's production dependency surface is limited to sillytavern-utils-lib, with all other declared packages being dev-only build tooling. If this advisory affects a dev-only transitive dependency, it does not reach the built extension artifact. The specific package name was not supplied, so production-vs-dev classification cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package. If it is a production dependency, prioritize updating immediately; if dev-only, update during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvcm-6775-5m9r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · medium confidence
A security scanner found a medium-severity issue in one of this project's dependencies. This is most likely in a development tool and would not affect users of the finished extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity known advisory against a declared dependency in the lockfile. The project structure indicates the vast majority of dependencies are dev-only build tooling. Medium-severity advisories in dev tooling transitive dependencies do not propagate to the shipped extension artifact.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package via npm audit and update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6 applies
Minor caution · medium confidence
A security scanner flagged a high-severity vulnerability in a dependency. This project relies mostly on development tools, so the issue likely affects only the build environment rather than the extension users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity known advisory against a declared dependency in the lockfile. The project declares only sillytavern-utils-lib as a production dependency; all other packages are dev-only build tooling. If this advisory is in a dev-only transitive dependency, it does not affect the built dist artifact. The specific package name was not supplied, preventing definitive production-vs-dev classification.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package. If it is a production dependency, prioritize updating immediately; if dev-only, update during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · medium confidence
A security scanner found a medium-severity known issue in one of this project's dependencies. This is most likely in a development tool and would not affect users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity known advisory against a declared dependency in the lockfile. The project's dependency tree is dominated by dev-only build tooling. Medium-severity advisories in dev tooling transitive dependencies do not reach the shipped extension artifact.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package via npm audit and update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-52cp-r559-cp3m applies
Minor caution · medium confidence
A security scanner flagged a high-severity vulnerability in a dependency. This project uses mostly development tools, so the issue likely affects only the build environment, not the extension that users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity known advisory against a declared dependency in the lockfile. The project declares only one production dependency (sillytavern-utils-lib) with all other packages being dev-only build tooling. If this advisory affects a dev-only transitive dependency, it does not propagate to the built extension artifact. The specific package name was not supplied, so production-vs-dev classification cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package. If it is a production dependency, prioritize updating immediately; if dev-only, update during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-52cp-r559-cp3m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project's package.json shows only one production dependency (sillytavern-utils-lib) while all other dependencies are devDependencies used for build, test, and type-checking (babel, webpack, jest, typescript, sass, prettier). Vulnerabilities in build-tool transitive dependencies are generally not reachable at runtime in a SillyTavern client extension. The specific vulnerable package and version were not included in the supplied evidence, preventing confirmation of whether it is a production or dev-only dependency.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. If the vulnerable package is a transitive dev dependency, a devDependency bump or npm override may be needed.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project's dependency tree is dominated by devDependencies for build and test tooling. Without the specific package name and version in the supplied evidence, the vulnerable package cannot be confirmed as production or dev-only, but the project structure strongly suggests these advisories target build-tool transitive dependencies that are not exercised at extension runtime.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. If the vulnerable package is a transitive dev dependency, a devDependency bump or npm override may be needed.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project declares only sillytavern-utils-lib as a production dependency; all other packages are devDependencies for build and test. The advisory most likely targets a transitive dependency of a build tool. The specific package identity was not provided in the evidence, so production reachability cannot be fully confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. If the vulnerable package is a transitive dev dependency, a devDependency bump or npm override may be needed.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-48c2-rrv3-qjmp applies
Minor caution · medium confidence
A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency in the lockfile. The project's production dependency surface is limited to sillytavern-utils-lib, with the remainder being build and test devDependencies. A medium-severity advisory in a build-tool transitive dependency is unlikely to be exploitable in the runtime context of a SillyTavern client extension.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-48c2-rrv3-qjmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-38r7-794h-5758 applies
Minor caution · medium confidence
A minor known security issue was found in one of the tools used to build or test this extension. The real-world risk is low. Updating the dependency is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency in the lockfile. Low-severity advisories in dependency trees dominated by devDependencies pose minimal runtime risk to a client-side SillyTavern extension. The specific package was not identified in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-38r7-794h-5758
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project's package.json shows only one production dependency while all other packages are devDependencies for build and test tooling. The advisory likely targets a transitive dependency of a build tool. The specific package identity was not provided in the evidence, preventing full confirmation of production reachability.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. If the vulnerable package is a transitive dev dependency, a devDependency bump or npm override may be needed.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Expected scanner matches (0)
None.