Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 17, 2024 via pnpm

@azure/identity 1.5.0

Provides credential implementations for Azure SDK libraries that can authenticate with Azure Active Directory
Package summary
Share
6
issues
2
high severity
license
1
meta
1
4
moderate severity
vulnerability
4
7
licenses
81
MIT
9
ISC
4
Apache-2.0
7
other licenses
BSD-3-Clause
3
0BSD
2
(MIT OR WTFPL)
1
(BSD-2-Clause OR MIT OR Apache-2.0)
1
Package created
27 Jun 2019
Version published
19 Jul 2021
Maintainers
2
Total deps
101
Direct deps
17
License
MIT

Issues

6

2 high severity issues

high
Recommendation: Validate that the license expression complies with your license policy
via: keytar@7.9.0
via: keytar@7.9.0
Collapse
Expand

4 moderate severity issues

moderate
Recommendation: Upgrade to version 9.0.0 or later
via: @azure/msal-node@1.0.0-beta.6
Recommendation: Upgrade to version 9.0.0 or later
via: @azure/msal-node@1.0.0-beta.6
Recommendation: Upgrade to version 9.0.0 or later
via: @azure/msal-node@1.0.0-beta.6
Recommendation: Upgrade to version 0.28.0 or later
via: @azure/msal-node@1.0.0-beta.6 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
81 Packages, Including:
@azure/abort-controller@2.1.2
@azure/core-auth@1.7.2
@azure/core-client@1.9.2
@azure/core-rest-pipeline@1.15.2
@azure/core-tracing@1.0.0-preview.12
@azure/core-tracing@1.1.2
@azure/core-util@1.9.0
@azure/identity@1.5.0
@azure/logger@1.1.2
@azure/msal-common@4.5.1
@azure/msal-node@1.0.0-beta.6
@types/node@20.12.7
@types/stoppable@1.1.3
agent-base@7.1.1
axios@0.21.4
base64-js@1.5.1
bl@4.1.0
buffer@5.7.1
call-bind@1.0.7
debug@4.3.4
decompress-response@6.0.0
deep-extend@0.6.0
define-data-property@1.1.4
end-of-stream@1.4.4
es-define-property@1.0.0
es-errors@1.3.0
events@3.3.0
follow-redirects@1.15.6
fs-constants@1.0.0
function-bind@1.1.2
get-intrinsic@1.2.4
github-from-package@0.0.0
gopd@1.0.1
has-property-descriptors@1.0.2
has-proto@1.0.3
has-symbols@1.0.3
hasown@2.0.2
http-proxy-agent@7.0.2
https-proxy-agent@7.0.4
is-docker@2.2.1
is-wsl@2.2.0
jsonwebtoken@8.5.1
jwa@1.4.1
jwa@2.0.0
jws@3.2.2
jws@4.0.0
keytar@7.9.0
lodash.includes@4.3.0
lodash.isboolean@3.0.3
lodash.isinteger@4.0.4

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
chownr@1.1.4
inherits@2.0.4
ini@1.3.8
lru-cache@6.0.0
once@1.4.0
semver@5.7.2
semver@7.6.0
wrappy@1.0.2
yallist@4.0.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
4 Packages, Including:
@opentelemetry/api@1.8.0
detect-libc@2.0.3
ecdsa-sig-formatter@1.0.11
tunnel-agent@0.6.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
buffer-equal-constant-time@1.0.1
ieee754@1.2.1
qs@6.12.1

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

(MIT OR WTFPL)

Permissive
1 Packages, Including:
expand-template@2.0.3

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

17
All Dependencies CSV
β“˜ This is a list of @azure/identity 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@azure/core-auth1.7.2145.91 kBMIT
prod
@azure/core-client1.9.21.41 MBMIT
prod
@azure/core-rest-pipeline1.15.21.88 MBMIT
prod
@azure/core-tracing1.0.0-preview.1233.6 kBMIT
prod
@azure/logger1.1.2120.76 kBMIT
prod
@azure/msal-node1.0.0-beta.6206.65 kBMIT
prod
4
@types/stoppable1.1.32.22 kBMIT
prod
axios0.21.498.72 kBMIT
prod
1
events3.3.016.19 kBMIT
prod
jws4.0.05.75 kBMIT
prod
keytar7.9.09.19 kBMIT
prod optional
2
msal1.4.18540.08 kBMIT
prod
open7.4.212.37 kBMIT
prod
qs6.12.1241.26 kBBSD-3-Clause
prod
stoppable1.1.03.18 kBMIT
prod
tslib2.6.215.59 kB0BSD
prod
uuid8.3.227.32 kBMIT
prod

Visualizations