Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 20, 2024 via pnpm

@bonfire-labs/bonfire-ai 1.5.13

Bonfire enables companies to create enterprise-grade ChatGPT, trained in their data
Package summary
Share
10
issues
4
high severity
vulnerability
1
license
2
meta
1
4
moderate severity
meta
4
2
low severity
license
2
13
licenses
895
MIT
49
ISC
24
BSD-3-Clause
49
other licenses
BSD-2-Clause
21
Apache-2.0
17
MIT-0
2
Unlicense
2
+ 6 more
Package created
12 Jul 2023
Version published
18 Sep 2023
Maintainers
2
Total deps
1017
Direct deps
25
License
MIT

Issues

10

4 high severity issues

high
Recommendation: None
via: react-spring@9.7.3
Recommendation: Read and validate the license terms
via: css-loader@6.10.0 & others
Recommendation: Validate that the package complies with your license policy
via: react-spring@9.7.3
via: css-loader@6.10.0 & others
Collapse
Expand

4 moderate severity issues

moderate
via: react-spring@9.7.3
via: @headlessui/react@1.7.18 & others
via: react-spring@9.7.3
via: react-spring@9.7.3
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: css-loader@6.10.0 & others
Recommendation: Read and validate the license terms
via: react-spring@9.7.3
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
895 Packages, Including:
@babel/code-frame@7.23.5
@babel/compat-data@7.23.5
@babel/core@7.23.9
@babel/generator@7.23.6
@babel/helper-annotate-as-pure@7.22.5
@babel/helper-builder-binary-assignment-operator-visitor@7.22.15
@babel/helper-compilation-targets@7.23.6
@babel/helper-create-class-features-plugin@7.23.10
@babel/helper-create-regexp-features-plugin@7.22.15
@babel/helper-define-polyfill-provider@0.5.0
@babel/helper-environment-visitor@7.22.20
@babel/helper-function-name@7.23.0
@babel/helper-hoist-variables@7.22.5
@babel/helper-member-expression-to-functions@7.23.0
@babel/helper-module-imports@7.22.15
@babel/helper-module-transforms@7.23.3
@babel/helper-optimise-call-expression@7.22.5
@babel/helper-plugin-utils@7.22.5
@babel/helper-remap-async-to-generator@7.22.20
@babel/helper-replace-supers@7.22.20
@babel/helper-simple-access@7.22.5
@babel/helper-skip-transparent-expression-wrappers@7.22.5
@babel/helper-split-export-declaration@7.22.6
@babel/helper-string-parser@7.23.4
@babel/helper-validator-identifier@7.22.20
@babel/helper-validator-option@7.23.5
@babel/helper-wrap-function@7.22.20
@babel/helpers@7.23.9
@babel/highlight@7.23.4
@babel/parser@7.23.9
@babel/plugin-bugfix-safari-id-destructuring-collision-in-function-expression@7.23.3
@babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining@7.23.3
@babel/plugin-bugfix-v8-static-class-fields-redefine-readonly@7.23.7
@babel/plugin-proposal-async-generator-functions@7.20.7
@babel/plugin-proposal-class-properties@7.18.6
@babel/plugin-proposal-export-default-from@7.23.3
@babel/plugin-proposal-nullish-coalescing-operator@7.18.6
@babel/plugin-proposal-numeric-separator@7.18.6
@babel/plugin-proposal-object-rest-spread@7.20.7
@babel/plugin-proposal-optional-catch-binding@7.18.6
@babel/plugin-proposal-optional-chaining@7.21.0
@babel/plugin-proposal-private-property-in-object@7.21.0-placeholder-for-preset-env.2
@babel/plugin-syntax-async-generators@7.8.4
@babel/plugin-syntax-class-properties@7.12.13
@babel/plugin-syntax-class-static-block@7.14.5
@babel/plugin-syntax-dynamic-import@7.8.3
@babel/plugin-syntax-export-default-from@7.23.3
@babel/plugin-syntax-export-namespace-from@7.8.3
@babel/plugin-syntax-flow@7.23.3
@babel/plugin-syntax-import-assertions@7.23.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
49 Packages, Including:
@isaacs/ttlcache@1.4.1
@ungap/structured-clone@1.2.0
anymatch@3.1.3
boolbase@1.0.0
cliui@6.0.0
cliui@8.0.1
electron-to-chromium@1.4.676
fastq@1.17.1
fs.realpath@1.0.0
get-caller-file@2.0.5
glob-parent@5.1.2
glob@7.2.3
graceful-fs@4.2.11
icss-utils@5.1.0
inflight@1.0.6
inherits@2.0.3
inherits@2.0.4
isexe@2.0.0
lru-cache@5.1.1
lru-cache@6.0.0
lucide-react@0.260.0
minimalistic-assert@1.0.1
minimatch@3.1.2
once@1.4.0
picocolors@1.0.0
postcss-modules-extract-imports@3.0.0
postcss-modules-scope@3.1.1
postcss-modules-values@4.0.0
require-main-filename@2.0.0
rimraf@2.6.3
rimraf@3.0.2
semver@5.7.2
semver@6.3.1
semver@7.6.0
set-blocking@2.0.0
setprototypeof@1.1.0
setprototypeof@1.2.0
signal-exit@3.0.7
which-module@2.0.1
which@2.0.2
wrappy@1.0.2
write-file-atomic@2.4.3
y18n@4.0.3
y18n@5.0.8
yallist@3.1.1
yallist@4.0.0
yaml@2.3.4
yargs-parser@18.1.3
yargs-parser@21.1.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
24 Packages, Including:
@hapi/hoek@9.3.0
@hapi/topo@5.1.0
@react-native/debugger-frontend@0.73.3
@sideway/address@4.1.5
@sideway/formula@3.0.1
@sideway/pinpoint@2.0.0
@sinonjs/commons@3.0.1
@sinonjs/fake-timers@10.3.0
@xtuc/ieee754@1.2.0
diff@5.2.0
flat@5.0.2
hoist-non-react-statics@3.3.2
ieee754@1.2.1
joi@17.12.1
makeerror@1.0.12
qs@6.11.0
react-transition-group@4.4.5
serialize-javascript@6.0.2
source-map-js@1.0.2
source-map@0.5.7
source-map@0.6.1
source-map@0.7.4
sprintf-js@1.0.3
tmpl@1.0.5

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
21 Packages, Including:
css-select@4.3.0
css-what@6.1.0
default-gateway@6.0.3
domelementtype@2.3.0
domhandler@4.3.1
domutils@2.8.0
entities@2.2.0
entities@4.5.0
eslint-scope@5.1.1
esprima@4.0.1
esrecurse@4.3.0
estraverse@4.3.0
estraverse@5.3.0
esutils@2.0.3
glob-to-regexp@0.4.1
jsc-android@250231.0.0
nth-check@2.1.1
regjsparser@0.9.1
terser@5.27.2
uri-js@4.4.1
webidl-conversions@3.0.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
17 Packages, Including:
@ampproject/remapping@2.2.1
@webassemblyjs/leb128@1.11.6
@xtuc/long@4.2.2
ansi-html-community@0.0.8
bser@2.1.1
chrome-launcher@0.15.2
chromium-edge-launcher@1.0.0
faye-websocket@0.11.4
fb-watchman@2.0.2
human-signals@2.1.0
lighthouse-logger@1.4.2
marky@1.2.5
thenby@1.3.4
typescript@5.3.3
walker@1.0.8
websocket-driver@0.7.4
websocket-extensions@0.1.4

MIT No Attribution

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
@csstools/selector-specificity@3.0.2
postcss-nesting@12.0.3

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
2 Packages, Including:
fs-monkey@1.0.5
memfs@3.5.3

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
jsc-safe-url@0.2.4
tslib@2.6.2

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

Creative Commons Attribution 4.0 International

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
caniuse-lite@1.0.30001588

(BSD-3-Clause OR GPL-2.0)

Permissive
1 Packages, Including:
node-forge@1.3.1

BSD

Invalid
Not OSI Approved
1 Packages, Including:
readline@1.3.0

(MIT OR CC0-1.0)

Public Domain
1 Packages, Including:
type-fest@0.7.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

25
All Dependencies CSV
β“˜ This is a list of @bonfire-labs/bonfire-ai 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@headlessui/react1.7.18449.32 kBMIT
prod
1
@react-spring/rafz9.7.312.04 kBMIT
prod
@tailwindcss/typography0.5.1012.89 kBMIT
prod
axios1.6.7455.64 kBMIT
prod
css-loader6.10.029.32 kBMIT
prod
2
1
esbuild-loader3.2.09.98 kBMIT
prod
2
1
framer-motion10.18.0502.76 kBMIT
prod
html-webpack-plugin5.6.030.35 kBMIT
prod
2
1
lucide-react0.260.01.63 MBISC
prod
postcss-cli10.1.07.22 kBMIT
prod
postcss-loader7.3.412.14 kBMIT
prod
2
1
postcss-nesting12.0.327.01 kBMIT-0
prod
react-cookie4.1.116.65 kBMIT
prod
react-dom18.2.01.04 MBMIT
prod peer
react-markdown8.0.754.1 kBMIT
prod
react-spring9.7.33.9 kBMIT
prod
3
3
2
react-transition-group4.4.547.63 kBBSD-3-Clause
prod
react18.2.079.25 kBMIT
prod peer
rehype-raw7.0.04.98 kBMIT
prod
style-loader3.3.418.52 kBMIT
prod
2
1
swr2.2.5605.78 kBMIT
prod
1
ts-loader9.5.162.73 kBMIT
prod
2
1
webpack-cli5.1.423.43 kBMIT
prod peer
2
1
webpack-dev-server4.15.1110.06 kBMIT
prod peer
2
1
webpack5.90.34.6 MBMIT
prod peer
2
1

Visualizations