TavernKeeper Scan Report

bmen25124/SillyTavern-Roadway

Commit 8bd72bd Reviewed

3 material concerns identified.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 high 3 material 29 low

What this review found

Dependency advisory GHSA-fv7c-fp4j-7gwp applies

Material concern · medium confidence

A high-severity security issue was found in one of the packages this project depends on. It may be in a development-only tool, but because the severity is high, it should be investigated and fixed to be safe.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The lockfile contains both devDependencies and one runtime dependency (sillytavern-utils-lib). Without the exact package-to-advisory mapping, a high-severity advisory could affect a transitive runtime dependency that ships in the built artifact, or it could be confined to build tooling. The high severity warrants attention regardless of whether the vulnerable package is dev-only or runtime.

Impact: medium · Exploitability: unlikely

Developer action: Identify which package is affected by this advisory and update it to a patched version. If it is a transitive runtime dependency, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fv7c-fp4j-7gwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-5c6j-r48x-rmvq applies

Material concern · medium confidence

A high-severity security issue was found in one of the packages this project depends on. Because it could potentially affect the extension that users install, it should be investigated and fixed promptly.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project has one runtime dependency (sillytavern-utils-lib) alongside numerous devDependencies. A high-severity advisory could reside in a transitive runtime dependency that ships in the built artifact or in build tooling. The high severity and the presence of a runtime dependency make this worth prioritizing.

Impact: medium · Exploitability: unlikely

Developer action: Identify which package is affected by this advisory and update it to a patched version. If it is a transitive runtime dependency, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5c6j-r48x-rmvq
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Material concern · medium confidence

A high-severity security issue was found in one of the packages this project depends on. It may be in a development tool, but the high severity means it should be investigated and resolved.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The lockfile includes a runtime dependency (sillytavern-utils-lib) and many devDependencies. Without the exact package-to-advisory mapping, a high-severity advisory warrants attention because it could affect a transitive runtime dependency included in the shipped artifact.

Impact: medium · Exploitability: unlikely

Developer action: Identify which package is affected by this advisory and update it to a patched version. If it is a transitive runtime dependency, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Minor cautions

Dependency advisory GHSA-v6h2-p8h4-qcjw applies

Minor caution · medium confidence

A low-severity security issue was found in one of the tools used to build this extension. Since these tools are only used during development and the final extension only ships the compiled output, this is unlikely to affect people who install the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency in the lockfile. The project's declared dependencies are predominantly build-time devDependencies (babel, webpack, jest, sass, typescript) for a browser extension that ships compiled JS and CSS. Low-severity advisories in build tooling do not flow into the runtime artifact users install.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6h2-p8h4-qcjw
File role
production
Source
package-lock.json

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Minor caution · medium confidence

A low-severity security issue was found in one of the development tools listed in this project. Because the extension only ships the final compiled files, this issue is unlikely to impact users who install it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency in the lockfile. The project ships a compiled browser extension; the majority of declared packages are devDependencies used only during the build. A low-severity vulnerability in build tooling has no direct path to the installed extension runtime.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh29-5h37-fv8m applies

Minor caution · medium confidence

A medium-severity security issue was found in one of the project's dependencies. It is likely in a development tool, so it probably does not affect users who install the extension, but it should still be addressed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency in the lockfile. The project is a browser extension that ships compiled output; most declared packages are build-time devDependencies. A medium-severity advisory in build tooling does not directly reach the installed extension, though the exact affected package is not specified in the evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh29-5h37-fv8m
File role
production
Source
package-lock.json

Dependency advisory GHSA-qj8w-gfj5-8c6v applies

Minor caution · medium confidence

A medium-severity security issue was found in one of the project's dependencies. Since the extension only ships compiled files, this is unlikely to affect users, but the dependency should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency in the lockfile. The extension ships compiled JS and CSS; the declared dependency tree is dominated by devDependencies. Without the exact package mapping, a medium-severity advisory in build tooling is unlikely to affect the runtime artifact.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qj8w-gfj5-8c6v
File role
production
Source
package-lock.json

Dependency advisory GHSA-968p-4wvh-cqc8 applies

Minor caution · medium confidence

A medium-severity security issue was found in one of the project's dependencies. It is likely in a development tool and probably does not affect users who install the extension, but it should be updated.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-968p-4wvh-cqc8 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency in the lockfile. The project ships a compiled browser extension and most declared packages are devDependencies. A medium-severity advisory in build tooling is unlikely to reach the installed extension runtime, though the exact affected package is not specified.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-968p-4wvh-cqc8
File role
production
Source
package-lock.json

Dependency advisory GHSA-2g4f-4pwh-qvx6 applies

Minor caution · medium confidence

A tool found a known security issue in one of the packages used to build this extension. Since the extension only ships the compiled output and not these build tools, end users are unlikely to be affected. The developer should still update the dependency.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a dependency declared in package-lock.json. The lockfile is dominated by build-time devDependencies (babel, webpack, jest, sass, typescript) that compile to dist/index.js and dist/style.css but do not ship to end users. The only production dependency is sillytavern-utils-lib. Without the specific package name, the vulnerable code is most likely in a transitive dev dependency that never executes in the installed extension runtime.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package and update it to a non-vulnerable version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2g4f-4pwh-qvx6
File role
production
Source
package-lock.json

Dependency advisory GHSA-v39h-62p7-jpjc applies

Minor caution · medium confidence

A tool found a high-severity security issue in a build or test dependency. Because these tools are only used during development and are not included in what users install, the risk to end users is low. The developer should update the affected package.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The project's dependency tree is primarily devDependencies for building and testing. The shipped extension consists of compiled static assets (dist/index.js, dist/style.css) loaded by SillyTavern. Build-tool vulnerabilities do not execute in the end-user runtime context. The advisory severity reflects the vulnerable package's own threat model, not necessarily this extension's exposure.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package via npm audit and upgrade to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-h67p-54hq-rp68 applies

Minor caution · medium confidence

A known security issue was found in a development dependency. Since it is not part of what users actually install, the risk is low. Updating is still recommended for good hygiene.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a dependency in package-lock.json. The lockfile contains mostly development tooling dependencies. The extension distributes compiled output only, so vulnerable build-time packages do not run in the user's SillyTavern environment.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify and update the affected package.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h67p-54hq-rp68
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Minor caution · medium confidence

A high-severity issue was found in a build or test tool dependency. These tools are not shipped to users, so the practical risk is low. The developer should still patch it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The project ships compiled static assets to SillyTavern users, not the node_modules tree. The vulnerable package is most likely a transitive dev dependency used during build or test, which does not execute at runtime for end users.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package and upgrade to a non-vulnerable version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-wf6x-7x77-mvgw applies

Minor caution · medium confidence

A known vulnerability was found in a development dependency that is not shipped to users. The risk to end users is low, but the developer should update the package.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The extension's runtime payload is compiled JavaScript and CSS. Development dependencies flagged in the lockfile do not execute in the SillyTavern extension context for end users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to find and update the affected dependency.

Scanner
osv-scanner 2.4.0
Rule
GHSA-wf6x-7x77-mvgw
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Minor caution · medium confidence

A security issue was found in a build or test tool. Since users only receive the compiled extension files, the risk is low. The developer should update the dependency.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The project's package.json declares almost exclusively devDependencies for building and testing, with only sillytavern-utils-lib as a production dependency. The compiled output is what SillyTavern loads, not the npm dependency tree.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package via npm audit and upgrade it.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · medium confidence

A known vulnerability was found in a development tool dependency. It does not ship to end users, so the practical risk is low. Updating is recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The vulnerable package is likely a transitive dependency of a build or test tool. The extension's shipped artifacts are compiled static files that do not include or execute these dependencies at runtime.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify and patch the affected package.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v56q-mh7h-f735 applies

Minor caution · medium confidence

A security issue was found in a build or test dependency that is not included in the installed extension. The risk to users is low, but the developer should update the package.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The project distributes compiled output to SillyTavern, not its npm dependency tree. Build-time and test-time dependencies flagged by the scanner do not execute in the end-user extension context.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package and upgrade to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v56q-mh7h-f735
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependency listings. This project is a browser extension that ships compiled files, so the vulnerable dependency is most likely a build-time tool that does not run when the extension is used. Updating dependencies is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-7p8r-x3mc-p8w7) against a dependency declared in package-lock.json. The package identity was stripped from the evidence, but the lockfile shows the project has one production dependency (sillytavern-utils-lib) and a set of build-tool devDependencies (babel, webpack, jest, sass, typescript, etc.). The extension ships compiled dist/index.js and dist/style.css to SillyTavern; node_modules and the lockfile are development artifacts. A vulnerable dev or transitive dependency would not normally be present in the runtime browser context. Without the specific package name and version, runtime impact cannot be confirmed, but the development-only exposure limits practical risk.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependency listings. Since this extension ships compiled files rather than the full dependency tree, the vulnerable package probably only affects the development build process. Updating it is recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-7r86-cg39-jmmj) against a dependency in package-lock.json. The affected package name was removed from the evidence. The lockfile context shows predominantly development build-tool dependencies and a single production dependency (sillytavern-utils-lib). The extension's runtime artifact is a compiled webpack bundle loaded in the SillyTavern browser context; node_modules are not shipped. A vulnerable development dependency is unlikely to affect end users but represents supply-chain hygiene debt.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-8fgc-7cc6-rx7x applies

Minor caution · medium confidence

A security scanner found a low-severity vulnerability in one of the project's dependencies. This is a minor issue that likely affects only the development toolchain, not the extension users use. Updating the dependency is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known low-severity advisory (GHSA-8fgc-7cc6-rx7x) against a dependency in package-lock.json. The affected package identity was stripped. Given the project's dependency profile (build tools as devDependencies, one production dependency), and that the extension ships a compiled bundle rather than node_modules, the low scanner severity and development-context exposure suggest minimal runtime risk.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8fgc-7cc6-rx7x
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependency listings. The extension ships compiled files, so the vulnerable dependency likely only affects the build process. Updating it is recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-r28c-9q8g-f849) against a dependency in package-lock.json. The package name was removed from the evidence. The lockfile shows build-tool devDependencies and a single production dependency (sillytavern-utils-lib). The extension runtime is a compiled webpack bundle in the browser; node_modules are not deployed. Without the specific package identity, runtime exploitation cannot be confirmed, but the development-artifact context limits practical risk.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-xvcm-6775-5m9r applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependencies. Since the extension delivers compiled files to users, the vulnerable package probably only affects development. Updating it is recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-xvcm-6775-5m9r) against a dependency in package-lock.json. The affected package identity was stripped. The project's dependency tree is dominated by development build tools, with sillytavern-utils-lib as the sole production dependency. The shipped extension is a compiled bundle; node_modules are not part of the runtime. Without confirming the specific package, runtime impact is uncertain but likely limited to the development environment.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvcm-6775-5m9r
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · medium confidence

A security scanner found a medium-severity vulnerability in one of the project's dependencies. This likely affects only the development toolchain, not the extension itself. Updating the dependency is recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known medium-severity advisory (GHSA-3v7f-55p6-f55p) against a dependency in package-lock.json. The package name was removed from the evidence. The project ships a compiled webpack bundle as its runtime artifact; the lockfile and node_modules are development artifacts. A medium-severity vulnerability in a development dependency is unlikely to affect end users but should be patched for supply-chain hygiene.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependencies. The extension ships compiled files, so the vulnerable package likely only affects the build process. Updating it is recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-4c8g-83qw-93j6) against a dependency in package-lock.json. The affected package identity was stripped from the evidence. The lockfile context shows development build-tool dependencies and one production dependency (sillytavern-utils-lib). The extension runtime is a compiled bundle in the browser; node_modules are not deployed. Without the specific package name, runtime exploitation cannot be confirmed, but the development-artifact context limits practical risk.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · medium confidence

A security scanner found a medium-severity vulnerability in one of the project's dependencies. This likely affects only the development toolchain, not the extension itself. Updating the dependency is recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known medium-severity advisory (GHSA-f886-m6hf-6m8v) against a dependency in package-lock.json. The package name was removed from the evidence. The project ships a compiled webpack bundle as its runtime artifact; the lockfile and node_modules are development artifacts. A medium-severity vulnerability in a development dependency is unlikely to affect end users but should be patched for supply-chain hygiene.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-52cp-r559-cp3m applies

Minor caution · medium confidence

A known security issue was found in a package used to build this extension. Because the extension is compiled before distribution, the affected build tool is not included in what users actually install. The risk to end users is low, but the developer should update the package.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency declared in package-lock.json. The project has one runtime dependency (sillytavern-utils-lib) and a large set of devDependencies for build tooling (babel, jest, webpack, sass, typescript). The flagged package is most likely a transitive dependency of these build tools rather than a runtime dependency shipped to end users. The extension is bundled via webpack into dist/index.js, so build-time dependencies do not ship in the installed extension. The vulnerability therefore primarily affects the developer build environment, not end users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-52cp-r559-cp3m
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · medium confidence

A known security issue was found in a package used during development. Since the extension is compiled before users install it, the affected package is not included in the final product. The risk is low, but the developer should update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a transitive dependency in package-lock.json. Given the project structure, the flagged package is most likely a transitive dependency of devDependencies such as jest, babel, webpack, or sass. The extension is bundled before distribution, so build-time transitive dependencies are not present in the shipped artifact. Impact is limited to the developer build environment.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Minor caution · medium confidence

A known security issue was found in a build tool dependency. The extension is compiled before distribution, so this package does not reach end users. The risk is low, but the developer should update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency in package-lock.json. The project bundles its output via webpack, and the only runtime dependency is sillytavern-utils-lib. The flagged package is most likely a transitive dependency of the build toolchain (babel, jest, webpack, sass, or their sub-dependencies) and is not shipped to end users. The vulnerability affects the build environment rather than the distributed extension.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A known security issue was found in a package used to build this extension. The compiled extension does not include this package, so end users are not affected. The risk is low, but the developer should update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency in package-lock.json. The project has extensive devDependencies for build tooling and a single runtime dependency. The flagged package is most likely a transitive dependency of the build toolchain and is not included in the bundled extension output. Impact is confined to the developer build environment.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Minor caution · medium confidence

A known security issue was found in a development dependency. Because the extension is compiled before distribution, this package is not part of what users install. The risk is low, but the developer should update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency in package-lock.json. The project bundles its source via webpack into dist/index.js, and the only runtime dependency is sillytavern-utils-lib. The flagged package is most likely a transitive dependency of devDependencies and does not ship in the installed extension. The vulnerability affects the build environment, not end users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-48c2-rrv3-qjmp applies

Minor caution · medium confidence

A known security issue was found in a build-time dependency. The final extension does not include this package, so end users are not affected. The risk is low, but the developer should update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a transitive dependency in package-lock.json. The project structure indicates the flagged package is most likely a transitive dependency of build tools such as babel, jest, webpack, or sass. The extension is bundled before distribution, so these transitive dependencies are not present in the shipped artifact. Impact is limited to the developer build environment.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-48c2-rrv3-qjmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-38r7-794h-5758 applies

Minor caution · medium confidence

A minor known security issue was found in a build-time dependency. The compiled extension does not include this package. The risk is low, but the developer should update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known low-severity advisory against a transitive dependency in package-lock.json. The project has one runtime dependency and a large set of build-tool devDependencies. The flagged package is most likely a transitive dependency of the build toolchain and is not shipped in the bundled extension. The low severity and build-time-only context further reduce end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-38r7-794h-5758
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A known security issue was found in a build tool dependency. The extension is compiled before distribution, so this package does not reach end users. The risk is low, but the developer should update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency in package-lock.json. The project bundles its output via webpack and has a single runtime dependency (sillytavern-utils-lib). The flagged package is most likely a transitive dependency of devDependencies such as babel, jest, webpack, or sass, and is not included in the shipped extension. The vulnerability affects the build environment rather than end users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json
Expected scanner matches (0)

None.

Coverage and limitations

Tools

Limitations

Technical scan identity