Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 11, 2024 via pnpm
Package summary
Share
19
issues
1
critical severity
vulnerability
1
11
high severity
vulnerability
5
license
2
meta
4
3
moderate severity
vulnerability
3
4
low severity
vulnerability
1
license
3
8
licenses
174
MIT
12
ISC
9
Apache-2.0
7
other licenses
BSD-2-Clause
3
Public Domain
1
CC-BY-3.0
1
CC0-1.0
1
+ 1 more
Package created
28 Jun 2019
Version published
5 Aug 2020
Maintainers
2
Total deps
202
Direct deps
31
License
Apache-2.0

Issues

19

1 critical severity issue

critical
Recommendation: Upgrade to version 0.2.4 or later
via: mkdirp@0.5.1 & others
Collapse
Expand

11 high severity issues

high
Recommendation: Upgrade to version 2.29.4 or later
via: moment@2.24.0
Recommendation: Upgrade to version 2.29.2 or later
via: moment@2.24.0
Recommendation: Upgrade to version 4.17.21 or later
via: @adpt/dom-parser@0.3.1 & others
Recommendation: Upgrade to version 2.2.2 or later
via: @adpt/utils@0.3.1
Recommendation: Upgrade to version 1.22.13 or later
via: @adpt/utils@0.3.1
Recommendation: Validate that the package complies with your license policy
via: @adpt/utils@0.3.1 & others
Recommendation: Read and validate the license terms
via: read-pkg-up@4.0.0
via: debug@4.1.1
via: graphql-tools@4.0.6
via: mkdirp@0.5.1 & others
via: graphql-tools@4.0.6
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.21 or later
via: @adpt/dom-parser@0.3.1 & others
Recommendation: Upgrade to version 0.2.1 or later
via: mkdirp@0.5.1 & others
Recommendation: Upgrade to version 0.5.0 or later
via: @adpt/dom-parser@0.3.1
Collapse
Expand

4 low severity issues

low
Recommendation: Upgrade to version 4.3.1 or later
via: debug@4.1.1
Recommendation: Read and validate the license terms
via: @adpt/utils@0.3.1 & others
Recommendation: Read and validate the license terms
via: read-pkg-up@4.0.0
Recommendation: Read and validate the license terms
via: read-pkg-up@4.0.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
174 Packages, Including:
@unboundedsystems/node-graceful@3.0.0-unb.1
@usys/collections-ts@0.0.2
@wry/equality@0.1.11
apollo-link@1.2.14
apollo-utilities@1.3.4
array-buffer-byte-length@1.0.1
array-uniq@1.0.2
array.prototype.reduce@1.0.7
arraybuffer.prototype.slice@1.0.3
async-lock@1.2.4
available-typed-arrays@1.0.7
call-bind@1.0.7
callsites@3.1.0
collections@5.1.13
cross-spawn@7.0.3
data-view-buffer@1.0.1
data-view-byte-length@1.0.1
data-view-byte-offset@1.0.0
debug@4.1.1
decamelize@4.0.0
deep-diff@1.0.2
define-data-property@1.1.4
define-properties@1.2.1
deprecated-decorator@0.1.6
end-of-stream@1.4.4
error-ex@1.3.2
es-abstract@1.23.3
es-array-method-boxes-properly@1.0.0
es-define-property@1.0.0
es-errors@1.3.0
es-object-atoms@1.0.0
es-set-tostringtag@2.0.3
es-to-primitive@1.2.1
eventemitter2@6.4.3
eventemitter3@3.1.2
execa@3.4.0
fast-json-stable-stringify@2.1.0
find-up@3.0.0
find-up@4.1.0
flush-write-stream@2.0.0
for-each@0.3.3
fs-extra@8.1.0
function-bind@1.1.2
function.prototype.name@1.1.6
functions-have-names@1.2.3
get-intrinsic@1.2.4
get-stream@5.2.0
get-symbol-description@1.0.2
global-dirs@2.0.1
globalthis@1.0.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
12 Packages, Including:
capture-exit@2.0.0
graceful-fs@4.2.11
hosted-git-info@2.8.9
inherits@2.0.4
ini@1.3.8
isexe@2.0.0
once@1.4.0
sax@1.3.0
semver@5.7.2
signal-exit@3.0.7
which@2.0.2
wrappy@1.0.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
9 Packages, Including:
@adpt/core@0.3.1
@adpt/dom-parser@0.3.1
@adpt/utils@0.3.1
@usys/fork-require@1.0.9-unb1
human-signals@1.1.1
spdx-correct@3.2.0
tslib@1.10.0
validate-npm-package-license@3.0.4
weak-map@1.0.8

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
css-what@2.1.3
normalize-package-data@2.5.0
yarn@1.22.0

Public Domain

Invalid
Not OSI Approved
1 Packages, Including:
jsonify@0.0.1

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
stream-buffers@3.0.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

31
All Dependencies CSV
β“˜ This is a list of @adpt/core 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@adpt/dom-parser0.3.111.08 kBApache-2.0
prod
1
2
@adpt/utils0.3.162.5 kBApache-2.0
prod
4
1
1
@usys/fork-require1.0.9-unb133.56 kBApache-2.0
prod
async-lock1.2.45.34 kBMIT
prod
callsites3.1.02.38 kBMIT
prod
css-what2.1.33.86 kBBSD-2-Clause
prod
debug4.1.121.26 kBMIT
prod
1
1
flush-write-stream2.0.02.48 kBMIT
prod
graphlib2.1.889.33 kBMIT
prod
1
1
graphql-tag2.10.117.24 kBMIT
prod
graphql-tools4.0.696.67 kBMIT
prod
2
graphql-type-json0.3.13.03 kBMIT
prod
graphql14.6.0379.58 kBMIT
prod peer
indent-string3.2.01.91 kBMIT
prod
json-stable-stringify1.0.14.42 kBMIT
prod
1
1
lodash4.17.19307.92 kBMIT
prod
1
1
mkdirp0.5.14.87 kBMIT
prod
1
1
1
moment2.24.0517.34 kBMIT
prod
2
node-json-db0.11.010.3 kBMIT
prod
1
1
1
p-defer3.0.01.96 kBMIT
prod
p-queue4.0.05.74 kBMIT
prod
p-settle2.1.02.11 kBMIT
prod
p-timeout3.2.02.7 kBMIT
prod
proper-lockfile3.2.07.36 kBMIT
prod
randomstring1.1.54.27 kBMIT
prod
read-pkg-up4.0.02.01 kBMIT
prod
1
2
ts-custom-error3.1.112.26 kBMIT
prod
tslib1.10.09.25 kBApache-2.0
prod
type-name2.0.24.42 kBMIT
prod
urn-lib1.2.08.4 kBMIT
prod
xmlbuilder15.1.161.4 kBMIT
prod

Visualizations