Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 12, 2024 via pnpm

@backstage/backend-common 0.20.1

Common functionality library for Backstage backends
Package summary
Share
15
issues
2
critical severity
license
2
7
high severity
license
1
meta
6
5
moderate severity
vulnerability
2
meta
3
1
low severity
license
1
15
licenses
469
MIT
146
Apache-2.0
39
ISC
26
other licenses
BSD-3-Clause
9
BSD-2-Clause
4
N/A
2
Unlicense
2
+ 8 more
Package created
30 Apr 2020
Version published
16 Jan 2024
Maintainers
3
Total deps
680
Direct deps
56
License
Apache-2.0

Issues

15

2 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: @backstage/backend-app-api@0.5.10 & others
Recommendation: Check the package code and files for license information
via: @backstage/backend-app-api@0.5.10 & others
Collapse
Expand

7 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: @backstage/backend-app-api@0.5.10 & others
via: @aws-sdk/abort-controller@3.374.0
via: dockerode@3.3.5
via: @kubernetes/client-node@0.20.0
via: @kubernetes/client-node@0.20.0
via: dockerode@3.3.5
via: @kubernetes/client-node@0.20.0
Collapse
Expand

5 moderate severity issues

moderate
Recommendation: None
via: @kubernetes/client-node@0.20.0
Recommendation: Upgrade to version 4.1.3 or later
via: @kubernetes/client-node@0.20.0
via: @backstage/backend-app-api@0.5.10 & others
via: @backstage/backend-app-api@0.5.10 & others
via: @backstage/backend-app-api@0.5.10 & others
Collapse
Expand

1 low severity issue

low
Recommendation: Read and validate the license terms
via: @backstage/backend-app-api@0.5.10 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
469 Packages, Including:
@azure/abort-controller@1.1.0
@azure/abort-controller@2.0.0
@azure/core-auth@1.6.0
@azure/core-client@1.8.0
@azure/core-rest-pipeline@1.14.0
@azure/core-tracing@1.0.1
@azure/core-util@1.7.0
@azure/identity@4.0.1
@azure/logger@1.0.4
@azure/msal-browser@3.9.0
@azure/msal-common@14.7.0
@azure/msal-node@2.6.3
@babel/runtime@7.23.9
@changesets/types@4.1.0
@colors/colors@1.6.0
@cspotcode/source-map-support@0.8.1
@dabh/diagnostics@2.0.3
@ioredis/commands@1.2.0
@jridgewell/resolve-uri@3.1.1
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.9
@keyv/memcache@1.4.1
@keyv/redis@2.8.4
@manypkg/find-root@1.1.0
@manypkg/get-packages@1.1.3
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@octokit/auth-app@4.0.13
@octokit/auth-oauth-app@5.0.6
@octokit/auth-oauth-device@4.0.5
@octokit/auth-oauth-user@2.1.2
@octokit/auth-token@3.0.4
@octokit/core@4.2.4
@octokit/endpoint@7.0.6
@octokit/graphql@5.0.6
@octokit/oauth-authorization-url@5.0.0
@octokit/oauth-methods@2.0.6
@octokit/openapi-types@18.1.1
@octokit/plugin-paginate-rest@6.1.2
@octokit/plugin-request-log@1.0.4
@octokit/plugin-rest-endpoint-methods@7.2.3
@octokit/request-error@3.0.3
@octokit/request@6.2.8
@octokit/rest@19.0.13
@octokit/tsconfig@1.0.2
@octokit/types@10.0.0
@octokit/types@9.3.2
@tootallnate/once@2.0.0
@tsconfig/node10@1.0.9

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
146 Packages, Including:
@aws-crypto/crc32@3.0.0
@aws-crypto/crc32c@3.0.0
@aws-crypto/ie11-detection@3.0.0
@aws-crypto/sha1-browser@3.0.0
@aws-crypto/sha256-browser@3.0.0
@aws-crypto/sha256-js@3.0.0
@aws-crypto/supports-web-crypto@3.0.0
@aws-crypto/util@3.0.0
@aws-sdk/abort-controller@3.374.0
@aws-sdk/client-cognito-identity@3.511.0
@aws-sdk/client-s3@3.511.0
@aws-sdk/client-sso-oidc@3.511.0
@aws-sdk/client-sso@3.511.0
@aws-sdk/client-sts@3.511.0
@aws-sdk/core@3.511.0
@aws-sdk/credential-provider-cognito-identity@3.511.0
@aws-sdk/credential-provider-env@3.511.0
@aws-sdk/credential-provider-http@3.511.0
@aws-sdk/credential-provider-ini@3.511.0
@aws-sdk/credential-provider-node@3.511.0
@aws-sdk/credential-provider-process@3.511.0
@aws-sdk/credential-provider-sso@3.511.0
@aws-sdk/credential-provider-web-identity@3.511.0
@aws-sdk/credential-providers@3.511.0
@aws-sdk/middleware-bucket-endpoint@3.511.0
@aws-sdk/middleware-expect-continue@3.511.0
@aws-sdk/middleware-flexible-checksums@3.511.0
@aws-sdk/middleware-host-header@3.511.0
@aws-sdk/middleware-location-constraint@3.511.0
@aws-sdk/middleware-logger@3.511.0
@aws-sdk/middleware-recursion-detection@3.511.0
@aws-sdk/middleware-sdk-s3@3.511.0
@aws-sdk/middleware-signing@3.511.0
@aws-sdk/middleware-ssec@3.511.0
@aws-sdk/middleware-user-agent@3.511.0
@aws-sdk/region-config-resolver@3.511.0
@aws-sdk/signature-v4-multi-region@3.511.0
@aws-sdk/token-providers@3.511.0
@aws-sdk/types@3.511.0
@aws-sdk/util-arn-parser@3.495.0
@aws-sdk/util-endpoints@3.511.0
@aws-sdk/util-locate-window@3.495.0
@aws-sdk/util-user-agent-browser@3.511.0
@aws-sdk/util-user-agent-node@3.511.0
@aws-sdk/util-utf8-browser@3.259.0
@aws-sdk/xml-builder@3.496.0
@backstage/backend-app-api@0.5.10
@backstage/backend-common@0.20.1
@backstage/backend-dev-utils@0.1.3
@backstage/backend-plugin-api@0.6.9

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
39 Packages, Including:
anymatch@3.1.3
chownr@1.1.4
chownr@2.0.0
cliui@8.0.1
deprecation@2.3.1
fastq@1.17.1
fs-minipass@2.1.0
fs.realpath@1.0.0
get-caller-file@2.0.5
glob-parent@5.1.2
glob@7.2.3
glob@8.1.0
graceful-fs@4.2.11
har-schema@2.0.0
inflight@1.0.6
inherits@2.0.4
json-stringify-safe@5.0.1
lru-cache@6.0.0
lru-cache@7.18.3
lru-cache@9.1.2
make-error@1.3.6
minimatch@3.1.2
minimatch@5.1.6
minipass@3.3.6
minipass@5.0.0
once@1.4.0
pg-int8@1.0.1
semver@7.6.0
setprototypeof@1.2.0
split-ca@1.0.1
split2@4.2.0
tar@6.2.0
universal-user-agent@6.0.1
wrappy@1.0.2
y18n@5.0.8
yallist@4.0.0
yaml@2.3.4
yargs-parser@21.1.1
zod-to-json-schema@3.22.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
bcrypt-pbkdf@1.0.2
buffer-equal-constant-time@1.0.1
diff@4.0.2
ieee754@1.2.1
qs@6.11.0
qs@6.5.3
sprintf-js@1.0.3
tough-cookie@2.5.0
typescript-json-schema@0.62.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
4 Packages, Including:
@yarnpkg/parsers@3.0.0
esprima@4.0.1
uri-js@4.4.1
webidl-conversions@3.0.1

N/A

N/A
2 Packages, Including:
pause@0.0.1
seq-queue@0.0.5

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
2 Packages, Including:
stream-buffers@3.0.2
tweetnacl@0.14.5

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

(BSD-3-Clause OR GPL-2.0)

Permissive
1 Packages, Including:
node-forge@1.3.1

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

BSD

Invalid
Not OSI Approved
1 Packages, Including:
pct-encode@1.0.2

(MIT AND BSD-3-Clause)

Permissive
1 Packages, Including:
sha.js@2.4.11

(MIT OR CC0-1.0)

Public Domain
1 Packages, Including:
type-fest@0.20.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

56
All Dependencies CSV
β“˜ This is a list of @backstage/backend-common 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@aws-sdk/abort-controller3.374.04.97 kBApache-2.0
prod
1
@aws-sdk/client-s33.511.02.86 MBApache-2.0
prod
@aws-sdk/credential-providers3.511.087.77 kBApache-2.0
prod
@aws-sdk/types3.511.047.33 kBApache-2.0
prod
@backstage/backend-app-api0.5.1070.04 kBApache-2.0
prod
2
1
3
1
@backstage/backend-dev-utils0.1.35.17 kBApache-2.0
prod
@backstage/backend-plugin-api0.6.917.24 kBApache-2.0
prod
2
1
1
1
@backstage/cli-common0.1.135.29 kBApache-2.0
prod
@backstage/config-loader1.6.156 kBApache-2.0
prod
@backstage/config1.1.121.39 kBApache-2.0
prod
@backstage/errors1.2.314.24 kBApache-2.0
prod
@backstage/integration-aws-node0.1.810.17 kBApache-2.0
prod
@backstage/integration1.8.0117.71 kBApache-2.0
prod
@backstage/types1.1.13.35 kBApache-2.0
prod
@google-cloud/storage7.7.0272.08 kBApache-2.0
prod
@keyv/memcache1.4.14.8 kBMIT
prod
@keyv/redis2.8.45.16 kBMIT
prod
@kubernetes/client-node0.20.0620.63 kBApache-2.0
prod
3
2
@manypkg/get-packages1.1.36.39 kBMIT
prod
2
@octokit/rest19.0.133.66 kBMIT
prod
@types/cors2.8.172.06 kBMIT
prod
@types/dockerode3.3.2311.46 kBMIT
prod
@types/express4.17.212.64 kBMIT
prod peer
@types/luxon3.4.224.1 kBMIT
prod
@types/webpack-env1.18.45 kBMIT
prod
archiver6.0.110.14 kBMIT
prod
base64-stream1.0.02.78 kBMIT
prod
compression1.7.47.64 kBMIT
prod
concat-stream2.0.03.7 kBMIT
prod
cors2.8.56.03 kBMIT
prod
dockerode3.3.519.85 kBApache-2.0
prod
2
express-promise-router4.1.19.71 kBMIT
prod
express4.18.254.5 kBMIT
prod peer
fs-extra10.1.016.52 kBMIT
prod
git-url-parse13.1.19.33 kBMIT
prod
helmet6.2.022.29 kBMIT
prod
isomorphic-git1.25.3729.67 kBMIT
prod
jose4.15.469.46 kBMIT
prod optional
keyv4.5.48.42 kBMIT
prod
knex3.1.0208.67 kBMIT
prod
1
lodash4.17.21311.49 kBMIT
prod
logform2.6.025.6 kBMIT
prod
luxon3.4.4925.34 kBMIT
prod
minimatch5.1.612.81 kBISC
prod
mysql22.3.3119.67 kBMIT
prod peer
1
node-fetch2.7.043.6 kBMIT
prod
p-limit3.1.03.19 kBMIT
prod
pg-connection-string2.6.23.67 kBMIT
prod peer
pg8.11.321.3 kBMIT
prod peer
raw-body2.5.28.45 kBMIT
prod
tar6.2.041.43 kBISC
prod
uuid8.3.227.32 kBMIT
prod
winston-transport4.7.011.56 kBMIT
prod
winston3.11.048.85 kBMIT
prod
yauzl2.10.018.26 kBMIT
prod
yn4.0.02.53 kBMIT
prod

Visualizations