Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Jan 23, 2024 via pnpm

@strapi/plugin-upload 4.13.6

Makes it easy to upload images and files to your Strapi Application.
Package summary
Share
19
issues
8
high severity
vulnerability
1
license
6
meta
1
6
moderate severity
vulnerability
1
meta
5
5
low severity
license
5
10
licenses
308
MIT
25
ISC
9
Apache-2.0
17
other licenses
BSD-3-Clause
7
SEE LICENSE IN LICENSE
4
0BSD
2
Unlicense
1
+ 3 more
Package created
30 Jul 2021
Version published
13 Sep 2023
Maintainers
8
Total deps
359
Direct deps
30
License
SEE LICENSE IN LICENSE

Issues

19

8 high severity issues

high
Recommendation: Upgrade to version 0.32.6 or later
via: sharp@0.32.0
Recommendation: Validate that the package complies with your license policy
via: @strapi/helper-plugin@4.13.6
Recommendation: Validate that the package complies with your license policy
via: @strapi/plugin-upload@4.13.6
Recommendation: Validate that the package complies with your license policy
via: @strapi/provider-upload-local@4.13.6
Recommendation: Validate that the package complies with your license policy
via: @strapi/provider-upload-local@4.13.6 & others
Recommendation: Read and validate the license terms
via: @strapi/design-system@1.10.1 & others
Recommendation: Validate that the license expression complies with your license policy
via: sharp@0.32.0
via: sharp@0.32.0
Collapse
Expand

6 moderate severity issues

moderate
Recommendation: Upgrade to version 1.6.0 or later
via: @strapi/helper-plugin@4.13.6 & others
via: @strapi/design-system@1.10.1 & others
via: @strapi/design-system@1.10.1 & others
via: @strapi/plugin-upload@4.13.6
via: @strapi/design-system@1.10.1 & others
via: @strapi/design-system@1.10.1 & others
Collapse
Expand

5 low severity issues

low
Recommendation: Read and validate the license terms
via: @strapi/helper-plugin@4.13.6
Recommendation: Read and validate the license terms
via: @strapi/plugin-upload@4.13.6
Recommendation: Read and validate the license terms
via: @strapi/provider-upload-local@4.13.6
Recommendation: Read and validate the license terms
via: @strapi/provider-upload-local@4.13.6 & others
Recommendation: Read and validate the license terms
via: @strapi/design-system@1.10.1 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
308 Packages, Including:
@babel/code-frame@7.23.5
@babel/compat-data@7.23.5
@babel/core@7.23.7
@babel/generator@7.23.6
@babel/helper-annotate-as-pure@7.22.5
@babel/helper-compilation-targets@7.23.6
@babel/helper-environment-visitor@7.22.20
@babel/helper-function-name@7.23.0
@babel/helper-hoist-variables@7.22.5
@babel/helper-module-imports@7.22.15
@babel/helper-module-transforms@7.23.3
@babel/helper-plugin-utils@7.22.5
@babel/helper-simple-access@7.22.5
@babel/helper-split-export-declaration@7.22.6
@babel/helper-string-parser@7.23.4
@babel/helper-validator-identifier@7.22.20
@babel/helper-validator-option@7.23.5
@babel/helpers@7.23.8
@babel/highlight@7.23.4
@babel/parser@7.23.6
@babel/plugin-syntax-jsx@7.23.3
@babel/runtime@7.23.8
@babel/template@7.22.15
@babel/traverse@7.23.7
@babel/types@7.23.6
@codemirror/autocomplete@6.12.0
@codemirror/commands@6.3.3
@codemirror/lang-json@6.0.1
@codemirror/language@6.10.0
@codemirror/lint@6.4.2
@codemirror/search@6.5.5
@codemirror/state@6.4.0
@codemirror/theme-one-dark@6.1.2
@codemirror/view@6.23.0
@emotion/babel-plugin@11.11.0
@emotion/cache@11.11.0
@emotion/hash@0.9.1
@emotion/is-prop-valid@0.8.8
@emotion/memoize@0.7.4
@emotion/memoize@0.8.1
@emotion/react@11.11.3
@emotion/serialize@1.1.3
@emotion/sheet@1.2.2
@emotion/stylis@0.8.5
@emotion/unitless@0.7.5
@emotion/unitless@0.8.1
@emotion/use-insertion-effect-with-fallbacks@1.0.1
@emotion/utils@1.2.1
@emotion/weak-memoize@0.3.1
@floating-ui/core@1.5.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
25 Packages, Including:
chownr@1.1.4
css-color-keywords@1.0.0
electron-to-chromium@1.4.642
fs.realpath@1.0.0
glob@7.2.3
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.3
inherits@2.0.4
ini@1.3.8
lru-cache@5.1.1
lru-cache@6.0.0
minimatch@3.1.2
nano-time@1.0.0
once@1.4.0
picocolors@1.0.0
rimraf@3.0.2
semver@6.3.1
semver@7.5.4
setprototypeof@1.1.0
setprototypeof@1.2.0
wrappy@1.0.2
yallist@3.1.1
yallist@4.0.0
yaml@1.10.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
9 Packages, Including:
@ampproject/remapping@2.2.1
@internationalized/date@3.5.1
@internationalized/number@3.5.0
@swc/helpers@0.5.3
detect-libc@2.0.2
formik@2.4.0
sharp@0.32.0
tunnel-agent@0.6.0
unload@2.2.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
7 Packages, Including:
hoist-non-react-statics@3.3.2
ieee754@1.2.1
intl-messageformat@10.3.4
qs@6.11.1
react-intl@6.4.1
react-transition-group@4.4.5
source-map@0.5.7

SEE LICENSE IN LICENSE

Invalid
Not OSI Approved
4 Packages, Including:
@strapi/helper-plugin@4.13.6
@strapi/plugin-upload@4.13.6
@strapi/provider-upload-local@4.13.6
@strapi/utils@4.13.6

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
big-integer@1.6.52

Creative Commons Attribution 4.0 International

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
caniuse-lite@1.0.30001579

(MIT OR WTFPL)

Permissive
1 Packages, Including:
expand-template@2.0.3

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

30
All Dependencies CSV
β“˜ This is a list of @strapi/plugin-upload 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@strapi/design-system1.10.1189.25 kBMIT
prod peer
1
4
1
@strapi/helper-plugin4.13.648.93 kBSEE LICENSE IN LICENSE
prod
2
5
2
@strapi/icons1.10.1103.59 kBMIT
prod peer
1
@strapi/provider-upload-local4.13.64.46 kBSEE LICENSE IN LICENSE
prod
2
2
@strapi/utils4.13.663.43 kBSEE LICENSE IN LICENSE
prod
1
1
axios1.5.0431.76 kBMIT
prod
1
byte-size7.0.15.39 kBMIT
prod
cropperjs1.6.0112.14 kBMIT
prod
date-fns2.30.0682.42 kBMIT
prod
formik2.4.0149.27 kBApache-2.0
prod
fs-extra10.0.032.9 kBMIT
prod
immer9.0.19237.82 kBMIT
prod
koa-range0.3.03.09 kBMIT
prod
koa-static5.0.02.95 kBMIT
prod
lodash4.17.21311.49 kBMIT
prod
mime-types2.1.355.46 kBMIT
prod
prop-types15.8.122.12 kBMIT
prod
qs6.11.150.74 kBBSD-3-Clause
prod
react-dnd15.1.283.31 kBMIT
prod
react-dom18.2.01.04 MBMIT
prod peer
react-helmet6.1.024.48 kBMIT
prod
react-intl6.4.145.76 kBBSD-3-Clause
prod
react-query3.39.3489.88 kBMIT
prod
react-redux8.1.169.11 kBMIT
prod
react-router-dom5.3.4140.85 kBMIT
prod peer
react-select5.7.0134.09 kBMIT
prod
react18.2.079.25 kBMIT
prod peer
sharp0.32.0119.69 kBApache-2.0
prod
3
styled-components5.3.3779.77 kBMIT
prod peer
1
1
yup0.32.952.76 kBMIT
prod

Visualizations