Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 29, 2024 via pnpm

@npmcli/git 2.0.7

a util for spawning git from npm CLI contexts
Package summary
Share
2
issues
2
moderate severity
vulnerability
2
3
licenses
14
ISC
5
MIT
1
BSD-2-Clause
Package created
9 Mar 2020
Version published
13 Apr 2021
Maintainers
5
Total deps
20
Direct deps
8
License
ISC

Issues

2

2 moderate severity issues

moderate
Recommendation: Upgrade to version 2.0.8 or later
via: @npmcli/git@2.0.7
Recommendation: Upgrade to version 2.0.8 or later
via: @npmcli/git@2.0.7
Collapse
Expand

Licenses

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
14 Packages, Including:
@npmcli/git@2.0.7
@npmcli/promise-spawn@1.3.2
hosted-git-info@4.1.0
infer-owner@1.0.4
isexe@2.0.0
lru-cache@6.0.0
npm-normalize-package-bin@1.0.1
npm-package-arg@8.1.5
npm-pick-manifest@6.1.1
promise-inflight@1.0.1
semver@7.6.0
validate-npm-package-name@3.0.0
which@2.0.2
yallist@4.0.0

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
builtins@1.0.3
err-code@2.0.3
mkdirp@1.0.4
promise-retry@2.0.1
retry@0.12.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
npm-install-checks@4.0.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

8
All Dependencies CSV
β“˜ This is a list of @npmcli/git 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@npmcli/promise-spawn1.3.22.76 kBISC
prod
lru-cache6.0.05.65 kBISC
prod
mkdirp1.0.46.51 kBMIT
prod
npm-pick-manifest6.1.17.37 kBISC
prod
promise-inflight1.0.11.63 kBISC
prod
promise-retry2.0.14 kBMIT
prod
semver7.6.026.57 kBISC
prod
which2.0.24.39 kBISC
prod

Visualizations