Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Oct 26, 2023 via pnpm

@rails/webpacker 5.4.4

Use webpack to manage app-like JavaScript modules in Rails
Package summary
Share
47
issues
15
high severity
vulnerability
2
license
1
meta
12
8
moderate severity
vulnerability
1
meta
7
24
low severity
license
24
10
licenses
695
MIT
74
ISC
23
CC0-1.0
33
other licenses
BSD-2-Clause
18
BSD-3-Clause
9
Apache-2.0
2
(MIT OR Apache-2.0)
1
+ 3 more
Package created
30 Aug 2017
Version published
13 Feb 2023
Maintainers
8
Total deps
825
Direct deps
38
License
MIT

Issues

47

15 high severity issues

high
Recommendation: Upgrade to version 5.1.2 or later
via: babel-loader@8.3.0 & others
Recommendation: Upgrade to version 2.0.1 or later
via: optimize-css-assets-webpack-plugin@5.0.8
Recommendation: Read and validate the license terms
via: @babel/core@7.23.2 & others
via: compression-webpack-plugin@4.0.1 & others
via: babel-loader@8.3.0 & others
via: core-js@3.33.1
via: postcss-preset-env@6.7.2
via: babel-loader@8.3.0 & others
via: babel-loader@8.3.0 & others
via: babel-loader@8.3.0 & others
via: babel-loader@8.3.0 & others
via: babel-loader@8.3.0 & others
via: optimize-css-assets-webpack-plugin@5.0.8
via: optimize-css-assets-webpack-plugin@5.0.8
via: babel-loader@8.3.0 & others
Collapse
Expand

8 moderate severity issues

moderate
Recommendation: Upgrade to version 8.4.31 or later
via: css-loader@3.6.0 & others
via: compression-webpack-plugin@4.0.1 & others
via: babel-loader@8.3.0 & others
via: babel-loader@8.3.0 & others
via: babel-loader@8.3.0 & others
via: babel-loader@8.3.0 & others
via: compression-webpack-plugin@4.0.1 & others
via: compression-webpack-plugin@4.0.1 & others
Collapse
Expand

24 low severity issues

low
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: optimize-css-assets-webpack-plugin@5.0.8
Recommendation: Read and validate the license terms
via: optimize-css-assets-webpack-plugin@5.0.8
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: postcss-preset-env@6.7.2
Recommendation: Read and validate the license terms
via: @babel/core@7.23.2 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
695 Packages, Including:
@babel/code-frame@7.22.13
@babel/compat-data@7.23.2
@babel/core@7.23.2
@babel/generator@7.23.0
@babel/helper-annotate-as-pure@7.22.5
@babel/helper-builder-binary-assignment-operator-visitor@7.22.15
@babel/helper-compilation-targets@7.22.15
@babel/helper-create-class-features-plugin@7.22.15
@babel/helper-create-regexp-features-plugin@7.22.15
@babel/helper-define-polyfill-provider@0.4.3
@babel/helper-environment-visitor@7.22.20
@babel/helper-function-name@7.23.0
@babel/helper-hoist-variables@7.22.5
@babel/helper-member-expression-to-functions@7.23.0
@babel/helper-module-imports@7.22.15
@babel/helper-module-transforms@7.23.0
@babel/helper-optimise-call-expression@7.22.5
@babel/helper-plugin-utils@7.22.5
@babel/helper-remap-async-to-generator@7.22.20
@babel/helper-replace-supers@7.22.20
@babel/helper-simple-access@7.22.5
@babel/helper-skip-transparent-expression-wrappers@7.22.5
@babel/helper-split-export-declaration@7.22.6
@babel/helper-string-parser@7.22.5
@babel/helper-validator-identifier@7.22.20
@babel/helper-validator-option@7.22.15
@babel/helper-wrap-function@7.22.20
@babel/helpers@7.23.2
@babel/highlight@7.22.20
@babel/parser@7.23.0
@babel/plugin-bugfix-safari-id-destructuring-collision-in-function-expression@7.22.15
@babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining@7.22.15
@babel/plugin-proposal-class-properties@7.18.6
@babel/plugin-proposal-object-rest-spread@7.20.7
@babel/plugin-proposal-private-property-in-object@7.21.0-placeholder-for-preset-env.2
@babel/plugin-syntax-async-generators@7.8.4
@babel/plugin-syntax-class-properties@7.12.13
@babel/plugin-syntax-class-static-block@7.14.5
@babel/plugin-syntax-dynamic-import@7.8.3
@babel/plugin-syntax-export-namespace-from@7.8.3
@babel/plugin-syntax-import-assertions@7.22.5
@babel/plugin-syntax-import-attributes@7.22.5
@babel/plugin-syntax-import-meta@7.10.4
@babel/plugin-syntax-json-strings@7.8.3
@babel/plugin-syntax-logical-assignment-operators@7.10.4
@babel/plugin-syntax-nullish-coalescing-operator@7.8.3
@babel/plugin-syntax-numeric-separator@7.10.4
@babel/plugin-syntax-object-rest-spread@7.8.3
@babel/plugin-syntax-optional-catch-binding@7.8.3
@babel/plugin-syntax-optional-chaining@7.8.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
74 Packages, Including:
@npmcli/fs@1.1.1
@webassemblyjs/helper-fsm@1.9.0
anymatch@2.0.0
anymatch@3.1.3
aproba@1.2.0
boolbase@1.0.0
browserify-sign@4.2.2
cacache@12.0.4
cacache@15.3.0
chownr@1.1.4
chownr@2.0.0
cliui@5.0.0
copy-concurrently@1.0.5
electron-to-chromium@1.4.567
figgy-pudding@3.5.2
flatted@3.2.9
fs-minipass@2.1.0
fs-write-stream-atomic@1.0.10
fs.realpath@1.0.0
get-caller-file@2.0.5
glob-parent@3.1.0
glob-parent@5.1.2
glob@7.2.3
graceful-fs@4.2.11
icss-utils@4.1.1
infer-owner@1.0.4
inflight@1.0.6
inherits@2.0.3
inherits@2.0.4
ini@1.3.8
is-resolvable@1.1.0
isexe@2.0.0
lru-cache@5.1.1
lru-cache@6.0.0
minimalistic-assert@1.0.1
minimatch@3.1.2
minipass-collect@1.0.2
minipass-flush@1.0.5
minipass-pipeline@1.2.4
minipass@3.3.6
minipass@5.0.0
move-concurrently@1.0.1
once@1.4.0
parse-asn1@5.1.6
picocolors@0.2.1
picocolors@1.0.0
postcss-color-gray@5.0.0
postcss-modules-extract-imports@2.0.0
postcss-modules-scope@2.2.0
postcss-modules-values@3.0.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
23 Packages, Including:
@csstools/convert-colors@1.4.0
css-blank-pseudo@0.1.4
css-has-pseudo@0.10.0
css-prefers-color-scheme@3.1.1
cssdb@4.4.0
mdn-data@2.0.14
mdn-data@2.0.4
postcss-color-functional-notation@2.0.1
postcss-color-mod-function@3.0.3
postcss-dir-pseudo-class@5.0.0
postcss-double-position-gradients@1.0.0
postcss-env-function@2.0.2
postcss-focus-visible@4.0.0
postcss-focus-within@3.0.0
postcss-gap-properties@2.0.0
postcss-image-set-function@3.0.1
postcss-lab-function@2.0.1
postcss-logical@3.0.0
postcss-nesting@7.0.1
postcss-overflow-shorthand@2.0.0
postcss-place@4.0.1
postcss-preset-env@6.7.2
postcss-pseudo-class-any-link@6.0.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
18 Packages, Including:
css-select@2.1.0
css-what@3.4.2
domelementtype@1.3.1
domelementtype@2.3.0
domutils@1.7.0
entities@2.2.0
eslint-scope@4.0.3
esprima@4.0.1
esrecurse@4.3.0
estraverse@4.3.0
estraverse@5.3.0
esutils@2.0.3
mississippi@3.0.0
nth-check@1.0.2
regjsparser@0.9.1
terser@4.8.1
terser@5.22.0
uri-js@4.4.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
@xtuc/ieee754@1.2.0
ieee754@1.2.1
qs@6.11.2
serialize-javascript@4.0.0
serialize-javascript@5.0.1
source-map-js@1.0.2
source-map@0.5.7
source-map@0.6.1
sprintf-js@1.0.3

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
@ampproject/remapping@2.2.1
@xtuc/long@4.2.2

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

Creative Commons Attribution 4.0 International

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
caniuse-lite@1.0.30001554

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

(MIT AND BSD-3-Clause)

Permissive
1 Packages, Including:
sha.js@2.4.11
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

38
All Dependencies CSV
β“˜ This is a list of @rails/webpacker 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@babel/core7.23.2179.91 kBMIT
prod peer
1
1
@babel/plugin-proposal-class-properties7.18.61.64 kBMIT
prod
1
1
@babel/plugin-proposal-object-rest-spread7.20.716.49 kBMIT
prod
1
1
@babel/plugin-syntax-dynamic-import7.8.31.42 kBMIT
prod
1
1
@babel/plugin-transform-destructuring7.23.018.51 kBMIT
prod
1
1
@babel/plugin-transform-regenerator7.22.102.72 kBMIT
prod
1
1
@babel/plugin-transform-runtime7.23.211.17 kBMIT
prod
1
1
@babel/preset-env7.23.231.72 kBMIT
prod
1
1
@babel/runtime7.23.251.6 kBMIT
prod
babel-loader8.3.013.58 kBMIT
prod
9
4
1
babel-plugin-dynamic-import-node2.3.34.92 kBMIT
prod
babel-plugin-macros2.8.011.05 kBMIT
prod
case-sensitive-paths-webpack-plugin2.4.08.19 kBMIT
prod
compression-webpack-plugin4.0.110.19 kBMIT
prod
9
7
core-js3.33.1275.05 kBMIT
prod
1
css-loader3.6.022.14 kBMIT
prod
8
5
file-loader6.2.09.82 kBMIT
prod
8
4
flatted3.2.912.78 kBISC
prod
glob7.2.315.08 kBISC
prod
js-yaml3.14.175.07 kBMIT
prod
mini-css-extract-plugin0.9.014.66 kBMIT
prod
8
4
optimize-css-assets-webpack-plugin5.0.86.07 kBMIT
prod
12
5
3
path-complete-extname1.0.03.91 kBMIT
prod
pnp-webpack-plugin1.7.04.46 kBMIT
prod
postcss-flexbugs-fixes4.2.13.11 kBMIT
prod
1
postcss-import12.0.110.89 kBMIT
prod
1
postcss-loader3.0.09.71 kBMIT
prod
1
postcss-preset-env6.7.231.47 kBCC0-1.0
prod
2
1
22
postcss-safe-parser4.0.27.36 kBMIT
prod
1
regenerator-runtime0.13.118.32 kBMIT
prod
sass-loader10.1.118.1 kBMIT
prod
8
4
sass1.69.5776.92 kBMIT
prod peer
style-loader1.3.013.05 kBMIT
prod
8
4
terser-webpack-plugin4.2.317.84 kBMIT
prod
9
7
webpack-assets-manifest3.1.110.16 kBMIT
prod
8
4
webpack-cli3.3.1241.55 kBMIT
prod peer
8
4
webpack-sources1.4.39.39 kBMIT
prod
webpack4.47.0304.77 kBMIT
prod peer
8
4

Visualizations