Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 28, 2024 via pnpm

@storybook/core 6.4.14

Storybook framework-agnostic API
Package summary
Share
34
issues
1
critical severity
license
1
19
high severity
vulnerability
3
license
3
meta
13
10
moderate severity
vulnerability
1
meta
9
4
low severity
license
4
16
licenses
1002
MIT
78
ISC
24
BSD-2-Clause
37
other licenses
BSD-3-Clause
13
Apache-2.0
10
(MIT OR CC0-1.0)
3
Unlicense
2
+ 9 more
Package created
7 Jan 2018
Version published
21 Jan 2022
Maintainers
8
Total deps
1141
Direct deps
7
License
MIT

Issues

34

1 critical severity issue

critical
Recommendation: Check the package code and files for license information
via: @storybook/core-server@6.4.14
Collapse
Expand

19 high severity issues

high
Recommendation: Upgrade to version 0.0.3 or later
via: @storybook/core-server@6.4.14
Recommendation: Upgrade to version 5.1.2 or later
via: @storybook/core-client@6.4.14 & others
Recommendation: Upgrade to version 5.3.4 or later
via: @storybook/core-server@6.4.14
Recommendation: Read and validate the license terms
via: @storybook/core-server@6.4.14 & others
Recommendation: Validate that the package complies with your license policy
via: @storybook/core-server@6.4.14
Recommendation: Read and validate the license terms
via: @storybook/core-server@6.4.14
via: @storybook/core-server@6.4.14
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-server@6.4.14
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-server@6.4.14
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 8.4.31 or later
via: @storybook/core-server@6.4.14
via: @storybook/core-server@6.4.14
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-client@6.4.14 & others
via: @storybook/core-server@6.4.14
via: @storybook/core-server@6.4.14
via: @storybook/core-server@6.4.14
via: @storybook/core-server@6.4.14
Collapse
Expand

4 low severity issues

low
Recommendation: Read and validate the license terms
via: @storybook/core-server@6.4.14 & others
Recommendation: Read and validate the license terms
via: @storybook/core-server@6.4.14
Recommendation: Read and validate the license terms
via: @storybook/core-server@6.4.14
Recommendation: Read and validate the license terms
via: @storybook/core-server@6.4.14
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
1002 Packages, Including:
@babel/code-frame@7.24.2
@babel/compat-data@7.24.4
@babel/core@7.12.9
@babel/core@7.24.4
@babel/generator@7.24.4
@babel/helper-annotate-as-pure@7.22.5
@babel/helper-builder-binary-assignment-operator-visitor@7.22.15
@babel/helper-compilation-targets@7.23.6
@babel/helper-create-class-features-plugin@7.24.4
@babel/helper-create-regexp-features-plugin@7.22.15
@babel/helper-define-polyfill-provider@0.1.5
@babel/helper-define-polyfill-provider@0.6.2
@babel/helper-environment-visitor@7.22.20
@babel/helper-function-name@7.23.0
@babel/helper-hoist-variables@7.22.5
@babel/helper-member-expression-to-functions@7.23.0
@babel/helper-module-imports@7.24.3
@babel/helper-module-transforms@7.23.3
@babel/helper-optimise-call-expression@7.22.5
@babel/helper-plugin-utils@7.10.4
@babel/helper-plugin-utils@7.24.0
@babel/helper-remap-async-to-generator@7.22.20
@babel/helper-replace-supers@7.24.1
@babel/helper-simple-access@7.22.5
@babel/helper-skip-transparent-expression-wrappers@7.22.5
@babel/helper-split-export-declaration@7.22.6
@babel/helper-string-parser@7.24.1
@babel/helper-validator-identifier@7.22.20
@babel/helper-validator-option@7.23.5
@babel/helper-wrap-function@7.22.20
@babel/helpers@7.24.4
@babel/highlight@7.24.2
@babel/parser@7.24.4
@babel/plugin-bugfix-firefox-class-in-computed-class-key@7.24.4
@babel/plugin-bugfix-safari-id-destructuring-collision-in-function-expression@7.24.1
@babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining@7.24.1
@babel/plugin-bugfix-v8-static-class-fields-redefine-readonly@7.24.1
@babel/plugin-proposal-class-properties@7.18.6
@babel/plugin-proposal-decorators@7.24.1
@babel/plugin-proposal-export-default-from@7.24.1
@babel/plugin-proposal-nullish-coalescing-operator@7.18.6
@babel/plugin-proposal-object-rest-spread@7.12.1
@babel/plugin-proposal-object-rest-spread@7.20.7
@babel/plugin-proposal-optional-chaining@7.21.0
@babel/plugin-proposal-private-methods@7.18.6
@babel/plugin-proposal-private-property-in-object@7.21.0-placeholder-for-preset-env.2
@babel/plugin-syntax-async-generators@7.8.4
@babel/plugin-syntax-class-properties@7.12.13
@babel/plugin-syntax-class-static-block@7.14.5
@babel/plugin-syntax-decorators@7.24.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
78 Packages, Including:
@npmcli/fs@1.1.1
@storybook/semver@7.3.2
@webassemblyjs/helper-fsm@1.9.0
ansi-align@3.0.1
anymatch@2.0.0
anymatch@3.1.3
aproba@1.2.0
aproba@2.0.0
are-we-there-yet@2.0.0
at-least-node@1.0.0
boolbase@1.0.0
browserify-sign@4.2.3
cacache@12.0.4
cacache@15.3.0
chownr@1.1.4
chownr@2.0.0
color-support@1.1.3
console-control-strings@1.1.0
copy-concurrently@1.0.5
electron-to-chromium@1.4.750
fastq@1.17.1
figgy-pudding@3.5.2
fs-minipass@2.1.0
fs-write-stream-atomic@1.0.10
fs.realpath@1.0.0
gauge@3.0.2
glob-parent@3.1.0
glob-parent@5.1.2
glob-promise@3.4.0
glob@7.2.3
graceful-fs@4.2.11
has-unicode@2.0.1
hosted-git-info@2.8.9
icss-utils@4.1.1
infer-owner@1.0.4
inflight@1.0.6
inherits@2.0.3
inherits@2.0.4
lru-cache@5.1.1
lru-cache@6.0.0
minimalistic-assert@1.0.1
minimatch@3.1.2
minipass-collect@1.0.2
minipass-flush@1.0.5
minipass-pipeline@1.2.4
minipass@3.3.6
minipass@5.0.0
move-concurrently@1.0.1
npmlog@5.0.1
once@1.4.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
24 Packages, Including:
css-select@4.3.0
css-what@6.1.0
domelementtype@2.3.0
domhandler@4.3.1
domutils@2.8.0
dotenv-expand@5.1.0
dotenv@8.6.0
entities@2.2.0
eslint-scope@4.0.3
eslint-scope@5.1.1
esrecurse@4.3.0
estraverse@4.3.0
estraverse@5.3.0
esutils@2.0.3
glob-to-regexp@0.4.1
mississippi@3.0.0
normalize-package-data@2.5.0
nth-check@2.1.1
regjsparser@0.9.1
terser@4.8.1
terser@5.30.4
uglify-js@3.17.4
uri-js@4.4.1
webidl-conversions@3.0.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
13 Packages, Including:
@xtuc/ieee754@1.2.0
highlight.js@10.7.3
hoist-non-react-statics@3.3.2
ieee754@1.2.1
qs@6.11.0
qs@6.12.1
serialize-javascript@4.0.0
serialize-javascript@5.0.1
serialize-javascript@6.0.2
source-map@0.5.7
source-map@0.6.1
source-map@0.7.4
synchronous-promise@2.0.17

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
10 Packages, Including:
@ampproject/remapping@2.3.0
@webassemblyjs/leb128@1.11.6
@xtuc/long@4.2.2
ansi-html-community@0.0.8
fuse.js@3.6.1
lazy-universal-dotenv@3.0.1
react-helmet-async@1.3.0
spdx-correct@3.2.0
typescript@5.4.5
validate-npm-package-license@3.0.4

(MIT OR CC0-1.0)

Public Domain
3 Packages, Including:
type-fest@0.20.2
type-fest@0.6.0
type-fest@0.8.1

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
2 Packages, Including:
fs-monkey@1.0.5
memfs@3.5.3

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

Creative Commons Attribution 4.0 International

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
caniuse-lite@1.0.30001613

BSD

Invalid
Not OSI Approved
1 Packages, Including:
glob-to-regexp@0.3.0

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

(MIT AND BSD-3-Clause)

Permissive
1 Packages, Including:
sha.js@2.4.11

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17

N/A

N/A
1 Packages, Including:
trim@0.0.1

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
1 Packages, Including:
tslib@2.6.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

7
All Dependencies CSV
β“˜ This is a list of @storybook/core 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@storybook/core-client6.4.1412.58 kBMIT
prod
11
4
@storybook/core-server6.4.1451.16 kBMIT
prod
1
19
10
4
react-dom17.0.2727.53 kBMIT
prod peer
react17.0.272.94 kBMIT
prod peer
typescript5.4.530.87 MBApache-2.0
prod peer
webpack4.47.0304.77 kBMIT
prod peer
8
4
webpack5.91.04.71 MBMIT
prod peer
1
1

Visualizations