TavernKeeper Scan Report

SillyTavern/Extension-CustomSliders

Commit 758aa6f Reviewed

No material or high-risk concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 high 0 material 14 low

What this review found

No material or high-risk item was identified.

Minor cautions

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Minor caution · medium confidence

A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version to keep the development environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Dependency advisory GHSA-v39h-62p7-jpjc applies

Minor caution · medium confidence

A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version to keep the development environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-h67p-54hq-rp68 applies

Minor caution · medium confidence

A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version to keep the development environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h67p-54hq-rp68
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Minor caution · medium confidence

A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version to keep the development environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · medium confidence

A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version to keep the development environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Minor caution · medium confidence

A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version to keep the development environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-6g55-p6wh-862q applies

Minor caution · medium confidence

A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version to keep the development environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6g55-p6wh-862q
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · medium confidence

A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version to keep the development environment secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Minor caution · medium confidence

A known security issue was found in a tool used to build this extension, not in the extension itself. The problem affects developers building from source, not people using the finished extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-4c8g-83qw-93j6) against a transitive dependency in the lockfile. The project declares only yaml as a production dependency; all other declared packages are devDependencies used for webpack builds and eslint linting. Vulnerable packages in the build tooling tree do not ship in the compiled dist/index.js output that end users load, limiting runtime exposure to the development environment.

Impact: low · Exploitability: unlikely

Developer action: Update affected dev dependencies to patched versions to keep the build environment current.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-qx2v-qp2m-jg93 applies

Minor caution · medium confidence

A known security issue was found in a build tool, not in the extension code that users run. This is a low-risk issue for end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-qx2v-qp2m-jg93) against a transitive dependency. The project's only production dependency is yaml; remaining packages are devDependencies for webpack and eslint. Build-time vulnerabilities do not propagate into the browser-loaded dist/index.js bundle.

Impact: low · Exploitability: unlikely

Developer action: Update affected dev dependencies to patched versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qx2v-qp2m-jg93
File role
production
Source
package-lock.json

Dependency advisory GHSA-52cp-r559-cp3m applies

Minor caution · medium confidence

A known security issue was found in a development tool for this extension. It does not affect the finished extension that users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-52cp-r559-cp3m) against a transitive dependency. Given the project structure, the flagged package is part of the webpack or eslint dev dependency tree, not the single production dependency yaml. The compiled extension output does not include build tooling packages.

Impact: low · Exploitability: unlikely

Developer action: Update affected dev dependencies to patched versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-52cp-r559-cp3m
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · medium confidence

A known security issue was found in a build or lint tool. It does not affect the extension users run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-fxqj-rqcc-2cmp) against a transitive dependency. The project ships only yaml as a production dependency; all other packages are devDependencies for the build and lint pipeline. These do not appear in the runtime bundle loaded by SillyTavern.

Impact: low · Exploitability: unlikely

Developer action: Update affected dev dependencies to patched versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A known security issue was found in a development tool. It does not affect the finished extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-mh99-v99m-4gvg) against a transitive dependency. The project's production dependency tree contains only yaml; the remaining packages are devDependencies for webpack and eslint. Build-time vulnerabilities do not reach the browser-loaded dist/index.js output.

Impact: low · Exploitability: unlikely

Developer action: Update affected dev dependencies to patched versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A known security issue was found in a build tool. It does not affect the extension that users install and run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-rgw5-rvv9-x895) against a transitive dependency. The project declares only yaml as a production dependency; all other packages are devDependencies for the webpack and eslint toolchain. These packages are not included in the compiled extension bundle that end users load.

Impact: low · Exploitability: unlikely

Developer action: Update affected dev dependencies to patched versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json
Expected scanner matches (0)

None.

Coverage and limitations

Tools

Limitations

Technical scan identity