What this review found
Dependency advisory GHSA-fv7c-fp4j-7gwp applies
Material concern · medium confidence
A high-severity security issue was found in one of the packages this project depends on. It may be in a development-only tool, but because the severity is high, it should be investigated and fixed to be safe.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The lockfile contains both devDependencies and one runtime dependency (sillytavern-utils-lib). Without the exact package-to-advisory mapping, a high-severity advisory could affect a transitive runtime dependency that ships in the built artifact, or it could be confined to build tooling. The high severity warrants attention regardless of whether the vulnerable package is dev-only or runtime.
Impact: medium · Exploitability: unlikely
Developer action: Identify which package is affected by this advisory and update it to a patched version. If it is a transitive runtime dependency, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fv7c-fp4j-7gwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5c6j-r48x-rmvq applies
Material concern · medium confidence
A high-severity security issue was found in one of the packages this project depends on. Because it could potentially affect the extension that users install, it should be investigated and fixed promptly.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project has one runtime dependency (sillytavern-utils-lib) alongside numerous devDependencies. A high-severity advisory could reside in a transitive runtime dependency that ships in the built artifact or in build tooling. The high severity and the presence of a runtime dependency make this worth prioritizing.
Impact: medium · Exploitability: unlikely
Developer action: Identify which package is affected by this advisory and update it to a patched version. If it is a transitive runtime dependency, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5c6j-r48x-rmvq
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2hh-gcrm-f6hx applies
Material concern · medium confidence
A high-severity security issue was found in one of the packages this project depends on. It may be in a development tool, but the high severity means it should be investigated and resolved.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The lockfile includes a runtime dependency (sillytavern-utils-lib) and many devDependencies. Without the exact package-to-advisory mapping, a high-severity advisory warrants attention because it could affect a transitive runtime dependency included in the shipped artifact.
Impact: medium · Exploitability: unlikely
Developer action: Identify which package is affected by this advisory and update it to a patched version. If it is a transitive runtime dependency, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx
- File role
- production
- Source
- package-lock.json
Minor cautions
Dependency advisory GHSA-v6h2-p8h4-qcjw applies
Minor caution · medium confidence
A low-severity security issue was found in one of the tools used to build this extension. Since these tools are only used during development and the final extension only ships the compiled output, this is unlikely to affect people who install the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency in the lockfile. The project's declared dependencies are predominantly build-time devDependencies (babel, webpack, jest, sass, typescript) for a browser extension that ships compiled JS and CSS. Low-severity advisories in build tooling do not flow into the runtime artifact users install.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6h2-p8h4-qcjw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4x5r-pxfx-6jf8 applies
Minor caution · medium confidence
A low-severity security issue was found in one of the development tools listed in this project. Because the extension only ships the final compiled files, this issue is unlikely to impact users who install it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency in the lockfile. The project ships a compiled browser extension; the majority of declared packages are devDependencies used only during the build. A low-severity vulnerability in build tooling has no direct path to the installed extension runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4x5r-pxfx-6jf8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh29-5h37-fv8m applies
Minor caution · medium confidence
A medium-severity security issue was found in one of the project's dependencies. It is likely in a development tool, so it probably does not affect users who install the extension, but it should still be addressed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency in the lockfile. The project is a browser extension that ships compiled output; most declared packages are build-time devDependencies. A medium-severity advisory in build tooling does not directly reach the installed extension, though the exact affected package is not specified in the evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh29-5h37-fv8m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qj8w-gfj5-8c6v applies
Minor caution · medium confidence
A medium-severity security issue was found in one of the project's dependencies. Since the extension only ships compiled files, this is unlikely to affect users, but the dependency should be updated.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency in the lockfile. The extension ships compiled JS and CSS; the declared dependency tree is dominated by devDependencies. Without the exact package mapping, a medium-severity advisory in build tooling is unlikely to affect the runtime artifact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qj8w-gfj5-8c6v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-968p-4wvh-cqc8 applies
Minor caution · medium confidence
A medium-severity security issue was found in one of the project's dependencies. It is likely in a development tool and probably does not affect users who install the extension, but it should be updated.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-968p-4wvh-cqc8 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency in the lockfile. The project ships a compiled browser extension and most declared packages are devDependencies. A medium-severity advisory in build tooling is unlikely to reach the installed extension runtime, though the exact affected package is not specified.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-968p-4wvh-cqc8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2g4f-4pwh-qvx6 applies
Minor caution · medium confidence
A tool found a known security issue in one of the packages used to build this extension. Since the extension only ships the compiled output and not these build tools, end users are unlikely to be affected. The developer should still update the dependency.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a dependency declared in package-lock.json. The lockfile is dominated by build-time devDependencies (babel, webpack, jest, sass, typescript) that compile to dist/index.js and dist/style.css but do not ship to end users. The only production dependency is sillytavern-utils-lib. Without the specific package name, the vulnerable code is most likely in a transitive dev dependency that never executes in the installed extension runtime.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package and update it to a non-vulnerable version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2g4f-4pwh-qvx6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v39h-62p7-jpjc applies
Minor caution · medium confidence
A tool found a high-severity security issue in a build or test dependency. Because these tools are only used during development and are not included in what users install, the risk to end users is low. The developer should update the affected package.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The project's dependency tree is primarily devDependencies for building and testing. The shipped extension consists of compiled static assets (dist/index.js, dist/style.css) loaded by SillyTavern. Build-tool vulnerabilities do not execute in the end-user runtime context. The advisory severity reflects the vulnerable package's own threat model, not necessarily this extension's exposure.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package via npm audit and upgrade to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v39h-62p7-jpjc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-h67p-54hq-rp68 applies
Minor caution · medium confidence
A known security issue was found in a development dependency. Since it is not part of what users actually install, the risk is low. Updating is still recommended for good hygiene.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a dependency in package-lock.json. The lockfile contains mostly development tooling dependencies. The extension distributes compiled output only, so vulnerable build-time packages do not run in the user's SillyTavern environment.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify and update the affected package.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h67p-54hq-rp68
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-q3j6-qgpj-74h6 applies
Minor caution · medium confidence
A high-severity issue was found in a build or test tool dependency. These tools are not shipped to users, so the practical risk is low. The developer should still patch it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The project ships compiled static assets to SillyTavern users, not the node_modules tree. The vulnerable package is most likely a transitive dev dependency used during build or test, which does not execute at runtime for end users.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package and upgrade to a non-vulnerable version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q3j6-qgpj-74h6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-wf6x-7x77-mvgw applies
Minor caution · medium confidence
A known vulnerability was found in a development dependency that is not shipped to users. The risk to end users is low, but the developer should update the package.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The extension's runtime payload is compiled JavaScript and CSS. Development dependencies flagged in the lockfile do not execute in the SillyTavern extension context for end users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to find and update the affected dependency.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-wf6x-7x77-mvgw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Minor caution · medium confidence
A security issue was found in a build or test tool. Since users only receive the compiled extension files, the risk is low. The developer should update the dependency.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The project's package.json declares almost exclusively devDependencies for building and testing, with only sillytavern-utils-lib as a production dependency. The compiled output is what SillyTavern loads, not the npm dependency tree.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package via npm audit and upgrade it.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
A known vulnerability was found in a development tool dependency. It does not ship to end users, so the practical risk is low. Updating is recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The vulnerable package is likely a transitive dependency of a build or test tool. The extension's shipped artifacts are compiled static files that do not include or execute these dependencies at runtime.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify and patch the affected package.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v56q-mh7h-f735 applies
Minor caution · medium confidence
A security issue was found in a build or test dependency that is not included in the installed extension. The risk to users is low, but the developer should update the package.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a dependency in package-lock.json. The project distributes compiled output to SillyTavern, not its npm dependency tree. Build-time and test-time dependencies flagged by the scanner do not execute in the end-user extension context.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package and upgrade to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v56q-mh7h-f735
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7 applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependency listings. This project is a browser extension that ships compiled files, so the vulnerable dependency is most likely a build-time tool that does not run when the extension is used. Updating dependencies is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-7p8r-x3mc-p8w7) against a dependency declared in package-lock.json. The package identity was stripped from the evidence, but the lockfile shows the project has one production dependency (sillytavern-utils-lib) and a set of build-tool devDependencies (babel, webpack, jest, sass, typescript, etc.). The extension ships compiled dist/index.js and dist/style.css to SillyTavern; node_modules and the lockfile are development artifacts. A vulnerable dev or transitive dependency would not normally be present in the runtime browser context. Without the specific package name and version, runtime impact cannot be confirmed, but the development-only exposure limits practical risk.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7r86-cg39-jmmj applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependency listings. Since this extension ships compiled files rather than the full dependency tree, the vulnerable package probably only affects the development build process. Updating it is recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-7r86-cg39-jmmj) against a dependency in package-lock.json. The affected package name was removed from the evidence. The lockfile context shows predominantly development build-tool dependencies and a single production dependency (sillytavern-utils-lib). The extension's runtime artifact is a compiled webpack bundle loaded in the SillyTavern browser context; node_modules are not shipped. A vulnerable development dependency is unlikely to affect end users but represents supply-chain hygiene debt.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8fgc-7cc6-rx7x applies
Minor caution · medium confidence
A security scanner found a low-severity vulnerability in one of the project's dependencies. This is a minor issue that likely affects only the development toolchain, not the extension users use. Updating the dependency is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known low-severity advisory (GHSA-8fgc-7cc6-rx7x) against a dependency in package-lock.json. The affected package identity was stripped. Given the project's dependency profile (build tools as devDependencies, one production dependency), and that the extension ships a compiled bundle rather than node_modules, the low scanner severity and development-context exposure suggest minimal runtime risk.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8fgc-7cc6-rx7x
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependency listings. The extension ships compiled files, so the vulnerable dependency likely only affects the build process. Updating it is recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-r28c-9q8g-f849) against a dependency in package-lock.json. The package name was removed from the evidence. The lockfile shows build-tool devDependencies and a single production dependency (sillytavern-utils-lib). The extension runtime is a compiled webpack bundle in the browser; node_modules are not deployed. Without the specific package identity, runtime exploitation cannot be confirmed, but the development-artifact context limits practical risk.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xvcm-6775-5m9r applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependencies. Since the extension delivers compiled files to users, the vulnerable package probably only affects development. Updating it is recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-xvcm-6775-5m9r) against a dependency in package-lock.json. The affected package identity was stripped. The project's dependency tree is dominated by development build tools, with sillytavern-utils-lib as the sole production dependency. The shipped extension is a compiled bundle; node_modules are not part of the runtime. Without confirming the specific package, runtime impact is uncertain but likely limited to the development environment.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvcm-6775-5m9r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · medium confidence
A security scanner found a medium-severity vulnerability in one of the project's dependencies. This likely affects only the development toolchain, not the extension itself. Updating the dependency is recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known medium-severity advisory (GHSA-3v7f-55p6-f55p) against a dependency in package-lock.json. The package name was removed from the evidence. The project ships a compiled webpack bundle as its runtime artifact; the lockfile and node_modules are development artifacts. A medium-severity vulnerability in a development dependency is unlikely to affect end users but should be patched for supply-chain hygiene.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6 applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependencies. The extension ships compiled files, so the vulnerable package likely only affects the build process. Updating it is recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory (GHSA-4c8g-83qw-93j6) against a dependency in package-lock.json. The affected package identity was stripped from the evidence. The lockfile context shows development build-tool dependencies and one production dependency (sillytavern-utils-lib). The extension runtime is a compiled bundle in the browser; node_modules are not deployed. Without the specific package name, runtime exploitation cannot be confirmed, but the development-artifact context limits practical risk.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · medium confidence
A security scanner found a medium-severity vulnerability in one of the project's dependencies. This likely affects only the development toolchain, not the extension itself. Updating the dependency is recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known medium-severity advisory (GHSA-f886-m6hf-6m8v) against a dependency in package-lock.json. The package name was removed from the evidence. The project ships a compiled webpack bundle as its runtime artifact; the lockfile and node_modules are development artifacts. A medium-severity vulnerability in a development dependency is unlikely to affect end users but should be patched for supply-chain hygiene.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit or osv-scanner locally to identify the specific package, then update it to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-52cp-r559-cp3m applies
Minor caution · medium confidence
A known security issue was found in a package used to build this extension. Because the extension is compiled before distribution, the affected build tool is not included in what users actually install. The risk to end users is low, but the developer should update the package.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency declared in package-lock.json. The project has one runtime dependency (sillytavern-utils-lib) and a large set of devDependencies for build tooling (babel, jest, webpack, sass, typescript). The flagged package is most likely a transitive dependency of these build tools rather than a runtime dependency shipped to end users. The extension is bundled via webpack into dist/index.js, so build-time dependencies do not ship in the installed extension. The vulnerability therefore primarily affects the developer build environment, not end users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-52cp-r559-cp3m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · medium confidence
A known security issue was found in a package used during development. Since the extension is compiled before users install it, the affected package is not included in the final product. The risk is low, but the developer should update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a transitive dependency in package-lock.json. Given the project structure, the flagged package is most likely a transitive dependency of devDependencies such as jest, babel, webpack, or sass. The extension is bundled before distribution, so build-time transitive dependencies are not present in the shipped artifact. Impact is limited to the developer build environment.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
A known security issue was found in a build tool dependency. The extension is compiled before distribution, so this package does not reach end users. The risk is low, but the developer should update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency in package-lock.json. The project bundles its output via webpack, and the only runtime dependency is sillytavern-utils-lib. The flagged package is most likely a transitive dependency of the build toolchain (babel, jest, webpack, sass, or their sub-dependencies) and is not shipped to end users. The vulnerability affects the build environment rather than the distributed extension.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A known security issue was found in a package used to build this extension. The compiled extension does not include this package, so end users are not affected. The risk is low, but the developer should update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency in package-lock.json. The project has extensive devDependencies for build tooling and a single runtime dependency. The flagged package is most likely a transitive dependency of the build toolchain and is not included in the bundled extension output. Impact is confined to the developer build environment.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A known security issue was found in a development dependency. Because the extension is compiled before distribution, this package is not part of what users install. The risk is low, but the developer should update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency in package-lock.json. The project bundles its source via webpack into dist/index.js, and the only runtime dependency is sillytavern-utils-lib. The flagged package is most likely a transitive dependency of devDependencies and does not ship in the installed extension. The vulnerability affects the build environment, not end users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-48c2-rrv3-qjmp applies
Minor caution · medium confidence
A known security issue was found in a build-time dependency. The final extension does not include this package, so end users are not affected. The risk is low, but the developer should update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a transitive dependency in package-lock.json. The project structure indicates the flagged package is most likely a transitive dependency of build tools such as babel, jest, webpack, or sass. The extension is bundled before distribution, so these transitive dependencies are not present in the shipped artifact. Impact is limited to the developer build environment.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-48c2-rrv3-qjmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-38r7-794h-5758 applies
Minor caution · medium confidence
A minor known security issue was found in a build-time dependency. The compiled extension does not include this package. The risk is low, but the developer should update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known low-severity advisory against a transitive dependency in package-lock.json. The project has one runtime dependency and a large set of build-tool devDependencies. The flagged package is most likely a transitive dependency of the build toolchain and is not shipped in the bundled extension. The low severity and build-time-only context further reduce end-user impact.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-38r7-794h-5758
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A known security issue was found in a build tool dependency. The extension is compiled before distribution, so this package does not reach end users. The risk is low, but the developer should update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a transitive dependency in package-lock.json. The project bundles its output via webpack and has a single runtime dependency (sillytavern-utils-lib). The flagged package is most likely a transitive dependency of devDependencies such as babel, jest, webpack, or sass, and is not included in the shipped extension. The vulnerability affects the build environment rather than end users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit fix or update the affected dependency tree to patched versions, then regenerate package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Expected scanner matches (0)
None.