What this review found
No material or high-risk item was identified.
Minor cautions
Dependency advisory GHSA-v2hh-gcrm-f6hx applies
Minor caution · medium confidence
A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v39h-62p7-jpjc applies
Minor caution · medium confidence
A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v39h-62p7-jpjc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-h67p-54hq-rp68 applies
Minor caution · medium confidence
A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h67p-54hq-rp68
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-q3j6-qgpj-74h6 applies
Minor caution · medium confidence
A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q3j6-qgpj-74h6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7 applies
Minor caution · medium confidence
A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-6g55-p6wh-862q applies
Minor caution · medium confidence
A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6g55-p6wh-862q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · medium confidence
A security issue was found in a tool used to build or test the extension. It does not appear to affect the extension itself once it is running in SillyTavern.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency in the lockfile. Given the project's dependency manifest, this is likely a development or build-time dependency rather than a runtime package used by the extension. Such vulnerabilities typically do not affect the final bundled extension or pose a direct risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6 applies
Minor caution · medium confidence
A known security issue was found in a tool used to build this extension, not in the extension itself. The problem affects developers building from source, not people using the finished extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-4c8g-83qw-93j6) against a transitive dependency in the lockfile. The project declares only yaml as a production dependency; all other declared packages are devDependencies used for webpack builds and eslint linting. Vulnerable packages in the build tooling tree do not ship in the compiled dist/index.js output that end users load, limiting runtime exposure to the development environment.
Impact: low · Exploitability: unlikely
Developer action: Update affected dev dependencies to patched versions to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qx2v-qp2m-jg93 applies
Minor caution · medium confidence
A known security issue was found in a build tool, not in the extension code that users run. This is a low-risk issue for end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-qx2v-qp2m-jg93) against a transitive dependency. The project's only production dependency is yaml; remaining packages are devDependencies for webpack and eslint. Build-time vulnerabilities do not propagate into the browser-loaded dist/index.js bundle.
Impact: low · Exploitability: unlikely
Developer action: Update affected dev dependencies to patched versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qx2v-qp2m-jg93
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-52cp-r559-cp3m applies
Minor caution · medium confidence
A known security issue was found in a development tool for this extension. It does not affect the finished extension that users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-52cp-r559-cp3m) against a transitive dependency. Given the project structure, the flagged package is part of the webpack or eslint dev dependency tree, not the single production dependency yaml. The compiled extension output does not include build tooling packages.
Impact: low · Exploitability: unlikely
Developer action: Update affected dev dependencies to patched versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-52cp-r559-cp3m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · medium confidence
A known security issue was found in a build or lint tool. It does not affect the extension users run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-fxqj-rqcc-2cmp) against a transitive dependency. The project ships only yaml as a production dependency; all other packages are devDependencies for the build and lint pipeline. These do not appear in the runtime bundle loaded by SillyTavern.
Impact: low · Exploitability: unlikely
Developer action: Update affected dev dependencies to patched versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A known security issue was found in a development tool. It does not affect the finished extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-mh99-v99m-4gvg) against a transitive dependency. The project's production dependency tree contains only yaml; the remaining packages are devDependencies for webpack and eslint. Build-time vulnerabilities do not reach the browser-loaded dist/index.js output.
Impact: low · Exploitability: unlikely
Developer action: Update affected dev dependencies to patched versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A known security issue was found in a build tool. It does not affect the extension that users install and run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-rgw5-rvv9-x895) against a transitive dependency. The project declares only yaml as a production dependency; all other packages are devDependencies for the webpack and eslint toolchain. These packages are not included in the compiled extension bundle that end users load.
Impact: low · Exploitability: unlikely
Developer action: Update affected dev dependencies to patched versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Expected scanner matches (0)
None.