Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 29, 2024 via pnpm

@pulumi/gcp 7.0.0

A Pulumi package for creating and managing Google Cloud Platform resources.
Package summary
Share
9
issues
6
high severity
license
2
meta
4
3
low severity
license
3
9
licenses
166
MIT
28
ISC
24
Apache-2.0
23
other licenses
BSD-3-Clause
14
BSD-2-Clause
5
SEE LICENSE IN LICENSE
1
(BSD-3-Clause AND Apache-2.0)
1
+ 2 more
Package created
31 Mar 2018
Version published
9 Nov 2023
Maintainers
2
Total deps
241
Direct deps
3
License
Apache-2.0

Issues

9

6 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: @pulumi/pulumi@3.107.0
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.107.0 & others
via: @pulumi/pulumi@3.107.0
via: @pulumi/pulumi@3.107.0
via: @pulumi/pulumi@3.107.0
via: @pulumi/pulumi@3.107.0
Collapse
Expand

3 low severity issues

low
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.107.0
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.107.0 & others
Recommendation: Read and validate the license terms
via: @pulumi/pulumi@3.107.0 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
166 Packages, Including:
@sindresorhus/is@4.6.0
@szmarczak/http-timer@4.0.6
@types/body-parser@1.19.5
@types/cacheable-request@6.0.3
@types/connect@3.4.38
@types/express-serve-static-core@4.17.43
@types/express@4.17.21
@types/google-protobuf@3.15.12
@types/http-cache-semantics@4.0.4
@types/http-errors@2.0.4
@types/keyv@3.1.4
@types/mime@1.3.5
@types/mime@3.0.4
@types/node@20.11.23
@types/qs@6.9.12
@types/range-parser@1.2.7
@types/responselike@1.0.3
@types/semver@7.5.8
@types/send@0.17.4
@types/serve-static@1.15.5
@types/tmp@0.2.6
ansi-regex@5.0.1
ansi-styles@4.3.0
argparse@1.0.10
array-buffer-byte-length@1.0.1
array.prototype.reduce@1.0.6
arraybuffer.prototype.slice@1.0.3
arrify@1.0.1
asap@2.0.6
available-typed-arrays@1.0.7
balanced-match@1.0.2
brace-expansion@1.1.11
buffer-from@1.1.2
cacheable-lookup@5.0.4
cacheable-request@7.0.4
call-bind@1.0.7
clone-response@1.0.3
color-convert@2.0.1
color-name@1.1.4
concat-map@0.0.1
cross-spawn@7.0.3
debug@4.3.4
debuglog@1.0.1
decompress-response@6.0.0
defer-to-connect@2.0.1
define-data-property@1.1.4
define-properties@1.2.1
emoji-regex@8.0.0
end-of-stream@1.4.4
es-abstract@1.22.5

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
28 Packages, Including:
cliui@8.0.1
dezalgo@1.0.4
fs.realpath@1.0.0
get-caller-file@2.0.5
glob@7.2.3
graceful-fs@4.2.11
hosted-git-info@2.8.9
hosted-git-info@4.1.0
inflight@1.0.6
inherits@2.0.4
ini@2.0.0
isexe@2.0.0
lru-cache@6.0.0
make-error@1.3.6
minimatch@3.1.2
npm-normalize-package-bin@1.0.1
once@1.4.0
read-package-json@2.1.2
read-package-tree@5.3.1
readdir-scoped-modules@1.1.0
semver@5.7.2
semver@7.6.0
signal-exit@3.0.7
which@2.0.2
wrappy@1.0.2
y18n@5.0.8
yallist@4.0.0
yargs-parser@21.1.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
24 Packages, Including:
@grpc/grpc-js@1.10.1
@grpc/proto-loader@0.7.10
@opentelemetry/api-metrics@0.32.0
@opentelemetry/api@1.8.0
@opentelemetry/context-async-hooks@1.22.0
@opentelemetry/core@1.22.0
@opentelemetry/exporter-zipkin@1.22.0
@opentelemetry/instrumentation-grpc@0.32.0
@opentelemetry/instrumentation@0.32.0
@opentelemetry/propagator-b3@1.22.0
@opentelemetry/propagator-jaeger@1.22.0
@opentelemetry/resources@1.22.0
@opentelemetry/sdk-trace-base@1.22.0
@opentelemetry/sdk-trace-node@1.22.0
@opentelemetry/semantic-conventions@1.22.0
@opentelemetry/semantic-conventions@1.6.0
@pulumi/gcp@7.0.0
@pulumi/pulumi@3.107.0
@pulumi/query@0.3.0
human-signals@2.1.0
long@5.2.3
spdx-correct@3.2.0
typescript@3.8.3
validate-npm-package-license@3.0.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
14 Packages, Including:
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
diff@3.5.0
protobufjs@7.2.6
source-map@0.6.1
sprintf-js@1.0.3

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
esprima@4.0.1
http-cache-semantics@4.1.1
normalize-package-data@2.5.0
normalize-package-data@3.0.3
shimmer@1.2.1

SEE LICENSE IN LICENSE

Invalid
Not OSI Approved
1 Packages, Including:
@logdna/tail-file@2.2.0

(BSD-3-Clause AND Apache-2.0)

Permissive
1 Packages, Including:
google-protobuf@3.21.2

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

3
All Dependencies CSV
β“˜ This is a list of @pulumi/gcp 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@pulumi/pulumi3.107.03.46 MBApache-2.0
prod
6
3
@types/express4.17.212.64 kBMIT
prod
read-package-json2.1.26.58 kBISC
prod
1
2

Visualizations