Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 9, 2024 via pnpm

@opentelemetry/sdk-node 0.34.0

OpenTelemetry SDK for Node.js
Package summary
Share
6
issues
3
critical severity
vulnerability
1
license
2
2
high severity
meta
2
1
moderate severity
meta
1
6
licenses
37
MIT
27
Apache-2.0
12
BSD-3-Clause
8
other licenses
ISC
5
N/A
2
BSD-2-Clause
1
Package created
27 Jul 2020
Version published
9 Nov 2022
Maintainers
3
Total deps
84
Direct deps
13
License
Apache-2.0

Issues

6

3 critical severity issues

critical
Recommendation: Upgrade to version 7.2.5 or later
via: @opentelemetry/exporter-trace-otlp-proto@0.34.0
Recommendation: Check the package code and files for license information
via: @opentelemetry/exporter-jaeger@1.8.0
Recommendation: Check the package code and files for license information
via: @opentelemetry/exporter-jaeger@1.8.0
Collapse
Expand

2 high severity issues

high
via: @opentelemetry/exporter-trace-otlp-proto@0.34.0
via: @opentelemetry/exporter-trace-otlp-grpc@0.34.0
Collapse
Expand

1 moderate severity issue

moderate
via: @opentelemetry/exporter-jaeger@1.8.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
37 Packages, Including:
@js-sdsl/ordered-map@4.4.2
@types/node@20.12.11
ansi-regex@5.0.1
ansi-styles@4.3.0
bufrw@1.4.0
color-convert@2.0.1
color-name@1.1.4
debug@4.3.4
emoji-regex@8.0.0
error@7.0.2
escalade@3.1.2
function-bind@1.1.2
hasown@2.0.2
hexer@1.5.0
is-core-module@2.13.1
is-fullwidth-code-point@3.0.0
lodash.camelcase@4.3.0
lodash.merge@4.6.2
minimist@1.2.8
module-details-from-path@1.0.3
ms@2.1.2
node-int64@0.4.0
path-parse@1.0.7
require-directory@2.1.1
require-in-the-middle@5.2.0
resolve@1.22.8
string-template@0.2.1
string-width@4.2.3
strip-ansi@6.0.1
supports-preserve-symlinks-flag@1.0.0
thriftrw@3.11.4
undici-types@5.26.5
uuid@8.3.2
wrap-ansi@7.0.0
xorshift@1.2.0
xtend@4.0.2
yargs@17.7.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
27 Packages, Including:
@grpc/grpc-js@1.10.7
@grpc/proto-loader@0.7.13
@opentelemetry/api@1.3.0
@opentelemetry/context-async-hooks@1.8.0
@opentelemetry/core@1.8.0
@opentelemetry/exporter-jaeger@1.8.0
@opentelemetry/exporter-trace-otlp-grpc@0.34.0
@opentelemetry/exporter-trace-otlp-http@0.34.0
@opentelemetry/exporter-trace-otlp-proto@0.34.0
@opentelemetry/exporter-zipkin@1.8.0
@opentelemetry/instrumentation@0.34.0
@opentelemetry/otlp-exporter-base@0.34.0
@opentelemetry/otlp-grpc-exporter-base@0.34.0
@opentelemetry/otlp-proto-exporter-base@0.34.0
@opentelemetry/otlp-transformer@0.34.0
@opentelemetry/propagator-b3@1.8.0
@opentelemetry/propagator-jaeger@1.8.0
@opentelemetry/resources@1.8.0
@opentelemetry/sdk-metrics@1.8.0
@opentelemetry/sdk-node@0.34.0
@opentelemetry/sdk-trace-base@1.8.0
@opentelemetry/sdk-trace-node@1.8.0
@opentelemetry/semantic-conventions@1.8.0
jaeger-client@3.19.0
long@2.4.0
long@5.2.3
opentracing@0.14.7

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
12 Packages, Including:
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
protobufjs@7.1.1
protobufjs@7.2.6

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
cliui@8.0.1
get-caller-file@2.0.5
semver@7.6.1
y18n@5.0.8
yargs-parser@21.1.1

N/A

N/A
2 Packages, Including:
ansi-color@0.2.1
process@0.10.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
shimmer@1.2.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

13
All Dependencies CSV
β“˜ This is a list of @opentelemetry/sdk-node 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@opentelemetry/api1.3.0102.17 kBApache-2.0
prod peer
@opentelemetry/core1.8.085.68 kBApache-2.0
prod
@opentelemetry/exporter-jaeger1.8.014.78 kBApache-2.0
prod
2
1
@opentelemetry/exporter-trace-otlp-grpc0.34.09.53 kBApache-2.0
prod
1
@opentelemetry/exporter-trace-otlp-http0.34.012.33 kBApache-2.0
prod
@opentelemetry/exporter-trace-otlp-proto0.34.08.48 kBApache-2.0
prod
1
1
@opentelemetry/exporter-zipkin1.8.026.85 kBApache-2.0
prod
@opentelemetry/instrumentation0.34.037.63 kBApache-2.0
prod
@opentelemetry/resources1.8.033.39 kBApache-2.0
prod
@opentelemetry/sdk-metrics1.8.0141.25 kBApache-2.0
prod
@opentelemetry/sdk-trace-base1.8.073.94 kBApache-2.0
prod
@opentelemetry/sdk-trace-node1.8.08.74 kBApache-2.0
prod
@opentelemetry/semantic-conventions1.8.0119.68 kBApache-2.0
prod

Visualizations