Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 21, 2024 via pnpm
Package summary
Share
13
issues
2
critical severity
license
2
5
high severity
license
2
meta
3
3
moderate severity
license
1
meta
2
3
low severity
license
3
13
licenses
441
MIT
68
Apache-2.0
50
ISC
36
other licenses
BSD-3-Clause
16
BSD-2-Clause
10
N/A
2
(MIT OR CC0-1.0)
2
+ 6 more
Package created
12 Aug 2019
Version published
15 Sep 2023
Maintainers
19
Total deps
595
Direct deps
55
License
MIT

Issues

13

2 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: @honeycombio/opentelemetry-node@0.5.0
Recommendation: Check the package code and files for license information
via: @honeycombio/opentelemetry-node@0.5.0
Collapse
Expand

5 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: @netlify/functions-utils@5.2.54 & others
Recommendation: Read and validate the license terms
via: @netlify/framework-info@9.8.11 & others
via: @netlify/functions-utils@5.2.54
via: @netlify/edge-bundler@8.20.0 & others
via: @honeycombio/opentelemetry-node@0.5.0
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Validate that the package complies with your license policy
via: @netlify/functions-utils@5.2.54 & others
via: @netlify/plugins-list@6.77.0
via: @honeycombio/opentelemetry-node@0.5.0
Collapse
Expand

3 low severity issues

low
Recommendation: Read and validate the license terms
via: @netlify/functions-utils@5.2.54 & others
Recommendation: Read and validate the license terms
via: @netlify/framework-info@9.8.11 & others
Recommendation: Read and validate the license terms
via: @netlify/framework-info@9.8.11 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
441 Packages, Including:
@babel/code-frame@7.24.2
@babel/helper-string-parser@7.24.1
@babel/helper-validator-identifier@7.22.20
@babel/highlight@7.24.2
@babel/parser@7.24.4
@babel/types@7.23.6
@babel/types@7.24.0
@bugsnag/browser@7.22.7
@bugsnag/core@7.22.7
@bugsnag/cuid@3.1.0
@bugsnag/js@7.22.7
@bugsnag/node@7.22.7
@bugsnag/safe-json-stringify@6.0.0
@cspotcode/source-map-support@0.8.1
@dependents/detective-less@4.1.0
@esbuild/aix-ppc64@0.19.11
@esbuild/android-arm64@0.19.11
@esbuild/android-arm64@0.19.2
@esbuild/android-arm@0.19.11
@esbuild/android-arm@0.19.2
@esbuild/android-x64@0.19.11
@esbuild/android-x64@0.19.2
@esbuild/darwin-arm64@0.19.11
@esbuild/darwin-arm64@0.19.2
@esbuild/darwin-x64@0.19.11
@esbuild/darwin-x64@0.19.2
@esbuild/freebsd-arm64@0.19.11
@esbuild/freebsd-arm64@0.19.2
@esbuild/freebsd-x64@0.19.11
@esbuild/freebsd-x64@0.19.2
@esbuild/linux-arm64@0.19.11
@esbuild/linux-arm64@0.19.2
@esbuild/linux-arm@0.19.11
@esbuild/linux-arm@0.19.2
@esbuild/linux-ia32@0.19.11
@esbuild/linux-ia32@0.19.2
@esbuild/linux-loong64@0.19.11
@esbuild/linux-loong64@0.19.2
@esbuild/linux-mips64el@0.19.11
@esbuild/linux-mips64el@0.19.2
@esbuild/linux-ppc64@0.19.11
@esbuild/linux-ppc64@0.19.2
@esbuild/linux-riscv64@0.19.11
@esbuild/linux-riscv64@0.19.2
@esbuild/linux-s390x@0.19.11
@esbuild/linux-s390x@0.19.2
@esbuild/linux-x64@0.19.11
@esbuild/linux-x64@0.19.2
@esbuild/netbsd-x64@0.19.11
@esbuild/netbsd-x64@0.19.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
68 Packages, Including:
@grpc/grpc-js@1.10.6
@grpc/proto-loader@0.7.12
@honeycombio/opentelemetry-node@0.5.0
@humanwhocodes/momoa@2.0.4
@opentelemetry/api-logs@0.39.1
@opentelemetry/api-logs@0.41.2
@opentelemetry/api@1.8.0
@opentelemetry/context-async-hooks@1.13.0
@opentelemetry/core@1.13.0
@opentelemetry/core@1.15.2
@opentelemetry/core@1.23.0
@opentelemetry/exporter-jaeger@1.13.0
@opentelemetry/exporter-metrics-otlp-grpc@0.41.2
@opentelemetry/exporter-metrics-otlp-http@0.39.1
@opentelemetry/exporter-metrics-otlp-http@0.41.2
@opentelemetry/exporter-metrics-otlp-proto@0.39.1
@opentelemetry/exporter-trace-otlp-grpc@0.39.1
@opentelemetry/exporter-trace-otlp-grpc@0.41.2
@opentelemetry/exporter-trace-otlp-http@0.39.1
@opentelemetry/exporter-trace-otlp-proto@0.39.1
@opentelemetry/exporter-trace-otlp-proto@0.41.2
@opentelemetry/exporter-zipkin@1.13.0
@opentelemetry/instrumentation@0.39.1
@opentelemetry/otlp-exporter-base@0.39.1
@opentelemetry/otlp-exporter-base@0.41.2
@opentelemetry/otlp-grpc-exporter-base@0.39.1
@opentelemetry/otlp-grpc-exporter-base@0.41.2
@opentelemetry/otlp-proto-exporter-base@0.39.1
@opentelemetry/otlp-proto-exporter-base@0.41.2
@opentelemetry/otlp-transformer@0.39.1
@opentelemetry/otlp-transformer@0.41.2
@opentelemetry/propagator-b3@1.13.0
@opentelemetry/propagator-jaeger@1.13.0
@opentelemetry/resources@1.13.0
@opentelemetry/resources@1.15.2
@opentelemetry/resources@1.23.0
@opentelemetry/sdk-logs@0.39.1
@opentelemetry/sdk-logs@0.41.2
@opentelemetry/sdk-metrics@1.13.0
@opentelemetry/sdk-metrics@1.15.2
@opentelemetry/sdk-metrics@1.23.0
@opentelemetry/sdk-node@0.39.1
@opentelemetry/sdk-trace-base@1.13.0
@opentelemetry/sdk-trace-base@1.15.2
@opentelemetry/sdk-trace-base@1.23.0
@opentelemetry/sdk-trace-node@1.13.0
@opentelemetry/semantic-conventions@1.13.0
@opentelemetry/semantic-conventions@1.15.2
@opentelemetry/semantic-conventions@1.23.0
b4a@1.6.6

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
50 Packages, Including:
@iarna/toml@2.2.5
abbrev@1.1.1
aproba@2.0.0
are-we-there-yet@2.0.0
chownr@2.0.0
cliui@8.0.1
color-support@1.1.3
common-path-prefix@3.0.0
console-control-strings@1.1.0
fastq@1.17.1
fs-minipass@2.1.0
fs.realpath@1.0.0
gauge@3.0.2
get-caller-file@2.0.5
glob-parent@5.1.2
glob@7.2.3
glob@8.1.0
graceful-fs@4.2.11
has-unicode@2.0.1
hosted-git-info@4.1.0
inflight@1.0.6
inherits@2.0.4
isexe@2.0.0
lru-cache@6.0.0
make-error@1.3.6
micro-api-client@3.3.0
minimatch@3.1.2
minimatch@5.1.6
minimatch@9.0.4
minipass@3.3.6
minipass@5.0.0
nopt@5.0.0
npmlog@5.0.1
once@1.4.0
picocolors@1.0.0
remove-trailing-separator@1.1.0
rimraf@3.0.2
semver@6.3.1
semver@7.6.0
set-blocking@2.0.0
signal-exit@3.0.7
tar@6.2.1
unix-dgram@2.0.6
validate-npm-package-name@4.0.0
which@2.0.2
wide-align@1.1.5
wrappy@1.0.2
y18n@5.0.8
yallist@4.0.0
yargs-parser@21.1.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
16 Packages, Including:
@mapbox/node-pre-gyp@1.0.11
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
diff@4.0.2
protobufjs@7.2.6
qs@6.12.1
source-map-js@1.2.0
source-map@0.6.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
10 Packages, Including:
@typescript-eslint/typescript-estree@5.62.0
escodegen@2.1.0
esprima@4.0.1
estraverse@5.3.0
esutils@2.0.3
http-cache-semantics@4.1.1
normalize-package-data@3.0.3
shimmer@1.2.1
uri-js@4.4.1
webidl-conversions@3.0.1

N/A

N/A
2 Packages, Including:
ansi-color@0.2.1
process@0.10.1

(MIT OR CC0-1.0)

Public Domain
2 Packages, Including:
type-fest@1.4.0
type-fest@2.19.0

Apache 2

Invalid
Not OSI Approved
1 Packages, Including:
@netlify/binary-info@1.0.0

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

Mozilla Public License 2.0

Weakly Protective
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
place-warranty
use-patent-claims
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
disclose-source
include-original
1 Packages, Including:
postcss-values-parser@6.0.2

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
1 Packages, Including:
tslib@1.14.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

55
All Dependencies CSV
β“˜ This is a list of @netlify/build 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@bugsnag/js7.22.73.45 kBMIT
prod
@honeycombio/opentelemetry-node0.5.016.9 kBApache-2.0
prod
2
1
1
@netlify/cache-utils5.1.57.33 kBMIT
prod
@netlify/config20.12.1131.22 kBMIT
prod
@netlify/edge-bundler8.20.01.05 MBMIT
prod
1
@netlify/framework-info9.8.11451.01 kBMIT
prod
1
2
@netlify/functions-utils5.2.548.17 kBMIT
prod
2
1
1
@netlify/git-utils5.1.14.82 kBMIT
prod
@netlify/plugins-list6.77.040.9 kBMIT
prod
1
@netlify/run-utils5.1.12.78 kBMIT
prod
@netlify/zip-it-and-ship-it9.18.160.15 kBMIT
prod
2
1
1
@opentelemetry/api1.8.01.15 MBApache-2.0
prod peer
@sindresorhus/slugify2.2.14.51 kBMIT
prod
ansi-escapes6.2.117.2 kBMIT
prod
chalk5.3.013.08 kBMIT
prod
clean-stack4.2.02.68 kBMIT
prod
execa6.1.014.31 kBMIT
prod
fdir6.1.113.46 kBMIT
prod
figures5.0.07.3 kBMIT
prod
filter-obj5.1.02.09 kBMIT
prod
got12.6.157.41 kBMIT
prod
hot-shots10.0.024.48 kBMIT
prod
indent-string5.0.02.18 kBMIT
prod
is-plain-obj4.1.01.92 kBMIT
prod
js-yaml4.1.099.96 kBMIT
prod
keep-func-props4.0.17.39 kBApache-2.0
prod
locate-path7.2.02.83 kBMIT
prod
log-process-errors8.0.029.94 kBApache-2.0
prod
map-obj5.0.23.02 kBMIT
prod
memoize-one6.0.09.36 kBMIT
prod
os-name5.1.02.44 kBMIT
prod
p-event5.0.15.9 kBMIT
prod
p-every2.0.02.42 kBMIT
prod
p-filter3.0.02.26 kBMIT
prod
p-locate6.0.03 kBMIT
prod
p-reduce3.0.02.52 kBMIT
prod
path-exists5.0.02.04 kBMIT
prod
path-type5.0.02.14 kBMIT
prod
pkg-dir7.0.02.19 kBMIT
prod
pretty-ms8.0.03.66 kBMIT
prod
ps-list8.1.1255.14 kBMIT
prod
read-pkg-up9.1.02.53 kBMIT
prod
1
2
readdirp3.6.07.38 kBMIT
prod
resolve2.0.0-next.524.78 kBMIT
prod
rfdc1.3.16.04 kBMIT
prod
safe-json-stringify1.2.06.03 kBMIT
prod
semver7.6.026.57 kBISC
prod
string-width5.1.22.5 kBMIT
prod
strip-ansi7.1.02.12 kBMIT
prod
supports-color9.4.04.35 kBMIT
prod
terminal-link3.0.02.44 kBMIT
prod
ts-node10.9.2192.13 kBMIT
prod
typescript5.4.530.87 MBApache-2.0
prod peer
uuid9.0.122.94 kBMIT
prod
yargs17.7.264.15 kBMIT
prod

Visualizations