Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 29, 2024 via pnpm

@expo/config 8.0.4

A library for interacting with the app.json
Package summary
Share
7
issues
2
high severity
license
2
3
moderate severity
vulnerability
2
meta
1
2
low severity
license
2
5
licenses
83
MIT
24
ISC
2
Unlicense
4
other licenses
BlueOak-1.0.0
2
Apache-2.0
2
Package created
29 Mar 2019
Version published
8 May 2023
Maintainers
27
Total deps
113
Direct deps
11
License
MIT

Issues

7

2 high severity issues

high
Recommendation: Read and validate the license terms
via: sucrase@3.35.0
Recommendation: Read and validate the license terms
via: sucrase@3.35.0
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Upgrade to version 0.5.0 or later
via: @expo/config-plugins@7.0.0
Recommendation: Upgrade to version 7.5.2 or later
via: semver@7.3.2
via: @expo/config-plugins@7.0.0
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: sucrase@3.35.0
Recommendation: Read and validate the license terms
via: sucrase@3.35.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
83 Packages, Including:
@babel/code-frame@7.10.4
@babel/helper-validator-identifier@7.22.20
@babel/highlight@7.23.4
@expo/config-plugins@7.0.0
@expo/config-types@49.0.0
@expo/config@8.0.4
@expo/json-file@8.2.37
@expo/json-file@8.3.0
@expo/plist@0.0.20
@expo/sdk-runtime-versions@1.0.0
@jridgewell/gen-mapping@0.3.4
@jridgewell/resolve-uri@3.1.2
@jridgewell/set-array@1.2.1
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.23
@pkgjs/parseargs@0.11.0
@react-native/normalize-color@2.1.0
@xmldom/xmldom@0.7.13
@xmldom/xmldom@0.8.10
ansi-regex@6.0.1
ansi-styles@3.2.1
ansi-styles@4.3.0
ansi-styles@6.2.1
any-promise@1.3.0
balanced-match@1.0.2
base64-js@1.5.1
bplist-creator@0.1.0
bplist-parser@0.3.1
brace-expansion@1.1.11
brace-expansion@2.0.1
chalk@2.4.2
chalk@4.1.2
color-convert@1.9.3
color-convert@2.0.1
color-name@1.1.3
color-name@1.1.4
commander@4.1.1
concat-map@0.0.1
cross-spawn@7.0.3
debug@4.3.4
eastasianwidth@0.2.0
emoji-regex@9.2.2
escape-string-regexp@1.0.5
find-up@5.0.0
getenv@1.0.0
has-flag@3.0.0
has-flag@4.0.0
imurmurhash@0.1.4
js-tokens@4.0.0
json5@2.2.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
24 Packages, Including:
@isaacs/cliui@8.0.2
foreground-child@3.1.1
fs.realpath@1.0.0
glob@10.3.10
glob@7.1.6
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
isexe@2.0.0
lru-cache@10.2.0
lru-cache@6.0.0
minimatch@3.1.2
minimatch@9.0.3
minipass@7.0.4
once@1.4.0
sax@1.3.0
semver@7.3.2
semver@7.6.0
signal-exit@3.0.7
signal-exit@4.1.0
which@2.0.2
wrappy@1.0.2
write-file-atomic@2.4.3
yallist@4.0.0

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
2 Packages, Including:
big-integer@1.6.52
stream-buffers@2.2.0

Blue Oak Model License 1.0.0

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
jackspeak@2.3.6
path-scurry@1.10.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
ts-interface-checker@0.1.13
xcode@3.0.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

11
All Dependencies CSV
β“˜ This is a list of @expo/config 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@babel/code-frame7.10.43.07 kBMIT
prod
@expo/config-plugins7.0.0247.75 kBMIT
prod
2
@expo/config-types49.0.012.13 kBMIT
prod
@expo/json-file8.3.06.98 kBMIT
prod
getenv1.0.03.92 kBMIT
prod
glob7.1.615.51 kBISC
prod
require-from-string2.0.21.77 kBMIT
prod
resolve-from5.0.02.28 kBMIT
prod
semver7.3.223.95 kBISC
prod
1
slugify1.6.68.5 kBMIT
prod
sucrase3.35.0189.24 kBMIT
prod
2
2

Visualizations