Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Generated on Dec 5, 2023 via pnpm

@microsoft/rush-lib 5.112.1

A library for writing scripts that interact with the Rush tool
Package summary
Share
10
issues
2
critical severity
license
2
4
high severity
license
2
meta
2
2
moderate severity
vulnerability
1
meta
1
2
low severity
license
2
14
licenses
431
MIT
54
ISC
9
BSD-2-Clause
28
other licenses
Apache-2.0
8
BSD-3-Clause
5
(MIT OR CC0-1.0)
5
N/A
2
+ 7 more
Package created
3 Jan 2017
Version published
29 Nov 2023
Maintainers
2
Total deps
522
Direct deps
39
License
MIT

Issues

10

2 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: npm-check@6.0.1
Recommendation: Check the package code and files for license information
via: cli-table@0.3.11
Collapse
Expand

4 high severity issues

high
Recommendation: Validate that the license expression complies with your license policy
via: npm-check@6.0.1
Recommendation: Read and validate the license terms
via: @pnpm/link-bins@5.3.25 & others
via: read-package-tree@5.1.6
via: read-package-tree@5.1.6
Collapse
Expand

2 moderate severity issues

moderate
Recommendation: Upgrade to version 11.8.5 or later
via: npm-check@6.0.1
via: npm-check@6.0.1
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: @pnpm/link-bins@5.3.25 & others
Recommendation: Read and validate the license terms
via: @pnpm/link-bins@5.3.25 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
431 Packages, Including:
@azure/abort-controller@1.1.0
@azure/core-auth@1.5.0
@azure/core-client@1.7.3
@azure/core-http@3.0.4
@azure/core-lro@2.5.4
@azure/core-paging@1.5.0
@azure/core-rest-pipeline@1.12.2
@azure/core-tracing@1.0.0-preview.13
@azure/core-tracing@1.0.1
@azure/core-util@1.6.1
@azure/identity@4.0.0
@azure/logger@1.0.4
@azure/msal-browser@3.6.0
@azure/msal-common@14.5.0
@azure/msal-node@2.6.0
@azure/storage-blob@12.17.0
@babel/code-frame@7.23.5
@babel/generator@7.23.5
@babel/helper-environment-visitor@7.22.20
@babel/helper-function-name@7.23.0
@babel/helper-hoist-variables@7.22.5
@babel/helper-split-export-declaration@7.22.6
@babel/helper-string-parser@7.23.4
@babel/helper-validator-identifier@7.22.20
@babel/highlight@7.23.4
@babel/parser@7.23.5
@babel/template@7.22.15
@babel/traverse@7.23.5
@babel/types@7.23.5
@devexpress/error-stack-parser@2.0.6
@jridgewell/gen-mapping@0.3.3
@jridgewell/resolve-uri@3.1.1
@jridgewell/set-array@1.1.2
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.20
@microsoft/rush-lib@5.112.1
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@pnpm/crypto.base32-hash@1.0.1
@pnpm/crypto.base32-hash@2.0.0
@pnpm/dependency-path@2.1.5
@pnpm/error@1.4.0
@pnpm/link-bins@5.3.25
@pnpm/package-bins@4.1.0
@pnpm/read-modules-dir@2.0.3
@pnpm/read-package-json@4.0.0
@pnpm/read-project-manifest@1.1.7
@pnpm/types@6.4.0
@pnpm/types@8.9.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
54 Packages, Including:
ansi-align@3.0.1
chownr@2.0.0
cli-width@3.0.0
cliui@7.0.4
dezalgo@1.0.4
fastq@1.15.0
fs-minipass@2.1.0
fs.realpath@1.0.0
get-caller-file@2.0.5
glob-parent@5.1.2
glob@7.2.3
graceful-fs@4.2.11
graceful-fs@4.2.4
hosted-git-info@2.8.9
hosted-git-info@4.1.0
ignore-walk@3.0.4
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
ini@2.0.0
isexe@2.0.0
lru-cache@6.0.0
minimatch@3.0.8
minimatch@3.1.2
minimatch@7.4.6
minipass@3.3.6
minipass@5.0.0
mute-stream@0.0.8
npm-bundled@1.1.2
npm-normalize-package-bin@1.0.1
npm-package-arg@6.1.1
npm-packlist@2.1.5
once@1.4.0
osenv@0.1.5
picocolors@1.0.0
read-package-json@2.1.2
read-package-tree@5.1.6
readdir-scoped-modules@1.1.0
sax@1.3.0
semver@5.7.2
semver@6.3.1
semver@7.5.4
signal-exit@3.0.7
ssri@8.0.1
tar@6.1.15
validate-npm-package-name@3.0.0
which@1.3.1
which@2.0.2
wrappy@1.0.2
write-file-atomic@3.0.3

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
@yarnpkg/lockfile@1.0.2
@zkochan/cmd-shim@5.4.1
configstore@5.0.1
esprima@4.0.1
http-cache-semantics@4.1.1
normalize-package-data@2.5.0
normalize-package-data@3.0.3
update-notifier@5.1.0
webidl-conversions@3.0.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
8 Packages, Including:
@opentelemetry/api@1.7.0
ecdsa-sig-formatter@1.0.11
find-yarn-workspace-root2@1.2.16
human-signals@2.1.0
rxjs@6.6.7
spdx-correct@3.2.0
true-case-path@2.2.1
validate-npm-package-license@3.0.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
buffer-equal-constant-time@1.0.1
duplexer3@0.1.5
ieee754@1.2.1
source-map-js@1.0.2
sprintf-js@1.0.3

(MIT OR CC0-1.0)

Public Domain
5 Packages, Including:
type-fest@0.18.1
type-fest@0.20.2
type-fest@0.21.3
type-fest@0.6.0
type-fest@0.8.1

N/A

N/A
2 Packages, Including:
callsite@1.0.0
cli-table@0.3.11

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

(MIT OR GPL-3.0-or-later)

Permissive
1 Packages, Including:
jszip@3.8.0

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.3.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.16
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

39
All Dependencies CSV
β“˜ This is a list of @microsoft/rush-lib 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@pnpm/dependency-path2.1.55.46 kBMIT
prod
@pnpm/link-bins5.3.254.71 kBMIT
prod
1
2
@rushstack/heft-config-file0.14.222.14 kBMIT
prod
@rushstack/node-core-library3.61.0241.12 kBMIT
prod
@rushstack/package-deps-hash4.1.1222.58 kBMIT
prod
@rushstack/package-extractor0.6.1440.68 kBMIT
prod
1
2
@rushstack/rig-package0.5.114.97 kBMIT
prod
@rushstack/rush-amazon-s3-build-cache-plugin5.112.127.15 kBMIT
prod
@rushstack/rush-azure-storage-build-cache-plugin5.112.120.12 kBMIT
prod
@rushstack/rush-http-build-cache-plugin5.112.161.69 kBMIT
prod
@rushstack/stream-collator4.1.139.15 kBMIT
prod
@rushstack/terminal0.7.1239.81 kBMIT
prod
@rushstack/ts-command-line4.17.189 kBMIT
prod
@types/node-fetch2.6.24.01 kBMIT
prod
@yarnpkg/lockfile1.0.268.77 kBBSD-2-Clause
prod
builtin-modules3.1.02.11 kBMIT
prod
cli-table0.3.115.94 kBUNKNOWN
prod
1
colors1.2.510.34 kBMIT
prod
dependency-path9.2.85.08 kBMIT
prod
fast-glob3.3.224.37 kBMIT
prod
figures3.0.03.79 kBMIT
prod
git-repo-info2.1.14.21 kBMIT
prod
glob-escape0.0.25.37 kBMIT
prod
https-proxy-agent5.0.18.21 kBMIT
prod
ignore5.1.913.16 kBMIT
prod
inquirer7.3.322.32 kBMIT
prod
js-yaml3.13.172.31 kBMIT
prod
node-fetch2.6.740.77 kBMIT
prod
npm-check6.0.119.67 kBMIT
prod
1
2
2
2
npm-package-arg6.1.15.79 kBISC
prod
read-package-tree5.1.63.9 kBISC
prod
3
2
rxjs6.6.7736.44 kBApache-2.0
prod
semver7.5.426.25 kBISC
prod
ssri8.0.113.76 kBISC
prod
strict-uri-encode2.0.01.48 kBMIT
prod
tapable2.2.110.64 kBMIT
prod
tar6.1.1540.87 kBISC
prod
true-case-path2.2.17.52 kBApache-2.0
prod
uuid8.3.227.32 kBMIT
prod

Visualizations