Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 9, 2024 via pnpm

@pulumi/digitalocean 4.21.0

A Pulumi package for creating and managing DigitalOcean cloud resources.
Package summary
Share
16
issues
9
high severity
license
4
meta
5
2
moderate severity
meta
2
5
low severity
license
5
10
licenses
211
MIT
102
ISC
32
Apache-2.0
27
other licenses
BSD-3-Clause
15
BSD-2-Clause
6
BlueOak-1.0.0
2
SEE LICENSE IN LICENSE
1
+ 3 more
Package created
21 May 2019
Version published
31 Jul 2023
Maintainers
2
Total deps
372
Direct deps
4
License
Apache-2.0

Issues

16

9 high severity issues

high
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.112.0
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.112.0
Recommendation: Validate that the package complies with your license policy
via: @pulumi/pulumi@3.112.0
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.112.0 & others
via: @pulumi/pulumi@3.112.0
via: @pulumi/digitalocean@4.21.0
via: @pulumi/pulumi@3.112.0
via: read-package-tree@5.3.1
via: read-package-tree@5.3.1
Collapse
Expand

2 moderate severity issues

moderate
via: @pulumi/pulumi@3.112.0
via: @pulumi/pulumi@3.112.0
Collapse
Expand

5 low severity issues

low
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.112.0
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.112.0
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.112.0
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.112.0 & others
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.112.0 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
211 Packages, Including:
@js-sdsl/ordered-map@4.4.2
@pkgjs/parseargs@0.11.0
@sindresorhus/is@4.6.0
@szmarczak/http-timer@4.0.6
@tufjs/canonical-json@2.0.0
@tufjs/models@2.0.0
@types/cacheable-request@6.0.3
@types/google-protobuf@3.15.12
@types/http-cache-semantics@4.0.4
@types/keyv@3.1.4
@types/node@20.12.5
@types/responselike@1.0.3
@types/semver@7.5.8
@types/tmp@0.2.6
agent-base@7.1.1
aggregate-error@3.1.0
ansi-regex@5.0.1
ansi-regex@6.0.1
ansi-styles@4.3.0
ansi-styles@6.2.1
argparse@1.0.10
array-buffer-byte-length@1.0.1
array.prototype.reduce@1.0.7
arraybuffer.prototype.slice@1.0.3
arrify@1.0.1
asap@2.0.6
available-typed-arrays@1.0.7
balanced-match@1.0.2
brace-expansion@1.1.11
brace-expansion@2.0.1
buffer-from@1.1.2
builtin-modules@3.0.0
builtins@5.1.0
cacheable-lookup@5.0.4
cacheable-request@7.0.4
call-bind@1.0.7
clean-stack@2.2.0
clone-response@1.0.3
color-convert@2.0.1
color-name@1.1.4
concat-map@0.0.1
cross-spawn@7.0.3
cssesc@3.0.0
data-view-buffer@1.0.1
data-view-byte-length@1.0.1
data-view-byte-offset@1.0.0
debug@4.3.4
debuglog@1.0.1
decompress-response@6.0.0
defer-to-connect@2.0.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
102 Packages, Including:
@isaacs/cliui@8.0.2
@isaacs/string-locale-compare@1.1.0
@npmcli/agent@2.2.2
@npmcli/arborist@7.4.1
@npmcli/fs@3.1.0
@npmcli/git@5.0.4
@npmcli/installed-package-contents@2.0.2
@npmcli/map-workspaces@3.0.4
@npmcli/metavuln-calculator@7.0.0
@npmcli/name-from-folder@2.0.0
@npmcli/node-gyp@3.0.0
@npmcli/package-json@5.0.0
@npmcli/promise-spawn@7.0.1
@npmcli/query@3.1.0
@npmcli/redact@1.1.0
@npmcli/run-script@7.0.4
abbrev@2.0.0
aproba@2.0.0
are-we-there-yet@4.0.2
bin-links@4.0.3
cacache@18.0.2
chownr@2.0.0
cliui@8.0.1
cmd-shim@6.0.2
color-support@1.1.3
common-ancestor-path@1.0.1
console-control-strings@1.1.0
dezalgo@1.0.4
foreground-child@3.1.1
fs-minipass@2.1.0
fs-minipass@3.0.3
fs.realpath@1.0.0
gauge@5.0.1
get-caller-file@2.0.5
glob@10.3.12
glob@7.2.3
graceful-fs@4.2.11
has-unicode@2.0.1
hosted-git-info@2.8.9
hosted-git-info@7.0.1
ignore-walk@6.0.4
inflight@1.0.6
inherits@2.0.4
ini@2.0.0
isexe@2.0.0
isexe@3.1.1
json-stringify-nice@1.1.4
lru-cache@10.2.0
lru-cache@6.0.0
make-error@1.3.6

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
32 Packages, Including:
@grpc/grpc-js@1.10.6
@grpc/proto-loader@0.7.12
@opentelemetry/api-metrics@0.32.0
@opentelemetry/api@1.8.0
@opentelemetry/context-async-hooks@1.23.0
@opentelemetry/core@1.23.0
@opentelemetry/exporter-zipkin@1.23.0
@opentelemetry/instrumentation-grpc@0.32.0
@opentelemetry/instrumentation@0.32.0
@opentelemetry/propagator-b3@1.23.0
@opentelemetry/propagator-jaeger@1.23.0
@opentelemetry/resources@1.23.0
@opentelemetry/sdk-trace-base@1.23.0
@opentelemetry/sdk-trace-node@1.23.0
@opentelemetry/semantic-conventions@1.23.0
@opentelemetry/semantic-conventions@1.6.0
@pulumi/digitalocean@4.21.0
@pulumi/pulumi@3.112.0
@pulumi/query@0.3.0
@sigstore/bundle@2.3.1
@sigstore/core@1.1.0
@sigstore/protobuf-specs@0.3.1
@sigstore/sign@2.3.0
@sigstore/tuf@2.3.2
@sigstore/verify@1.2.0
exponential-backoff@3.1.1
human-signals@2.1.0
long@5.2.3
sigstore@2.3.0
spdx-correct@3.2.0
typescript@3.8.3
validate-npm-package-license@3.0.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
15 Packages, Including:
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
diff@3.5.0
protobufjs@7.2.6
source-map@0.6.1
sprintf-js@1.0.3
sprintf-js@1.1.3

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
6 Packages, Including:
esprima@4.0.1
http-cache-semantics@4.1.1
normalize-package-data@2.5.0
normalize-package-data@6.0.0
npm-install-checks@6.3.0
shimmer@1.2.1

Blue Oak Model License 1.0.0

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
jackspeak@2.3.6
path-scurry@1.10.2

SEE LICENSE IN LICENSE

Invalid
Not OSI Approved
1 Packages, Including:
@logdna/tail-file@2.2.0

(BSD-3-Clause AND Apache-2.0)

Permissive
1 Packages, Including:
google-protobuf@3.21.2

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

4
All Dependencies CSV
β“˜ This is a list of @pulumi/digitalocean 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@pulumi/pulumi3.112.03.28 MBApache-2.0
prod
6
2
5
builtin-modules3.0.01.92 kBMIT
prod
read-package-tree5.3.15.14 kBISC
prod
3
2
resolve1.22.826.69 kBMIT
prod

Visualizations