Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 31, 2024 via pnpm

@sveltejs/kit 2.0.4

The fastest way to build Svelte apps
Package summary
Share
5
issues
4
high severity
vulnerability
2
meta
2
1
low severity
license
1
5
licenses
83
MIT
3
Apache-2.0
2
ISC
2
other licenses
CC0-1.0
1
BSD-3-Clause
1
Package created
14 Oct 2020
Version published
19 Dec 2023
Maintainers
4
Total deps
90
Direct deps
14
License
MIT

Issues

5

4 high severity issues

high
Recommendation: Upgrade to version 2.4.3 or later
via: @sveltejs/kit@2.0.4
Recommendation: Upgrade to version 2.4.3 or later
via: @sveltejs/kit@2.0.4
via: @sveltejs/kit@2.0.4
via: @sveltejs/vite-plugin-svelte@3.0.2 & others
Collapse
Expand

1 low severity issue

low
Recommendation: Read and validate the license terms
via: @sveltejs/vite-plugin-svelte@3.0.2 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
83 Packages, Including:
@esbuild/aix-ppc64@0.20.2
@esbuild/android-arm64@0.20.2
@esbuild/android-arm@0.20.2
@esbuild/android-x64@0.20.2
@esbuild/darwin-arm64@0.20.2
@esbuild/darwin-x64@0.20.2
@esbuild/freebsd-arm64@0.20.2
@esbuild/freebsd-x64@0.20.2
@esbuild/linux-arm64@0.20.2
@esbuild/linux-arm@0.20.2
@esbuild/linux-ia32@0.20.2
@esbuild/linux-loong64@0.20.2
@esbuild/linux-mips64el@0.20.2
@esbuild/linux-ppc64@0.20.2
@esbuild/linux-riscv64@0.20.2
@esbuild/linux-s390x@0.20.2
@esbuild/linux-x64@0.20.2
@esbuild/netbsd-x64@0.20.2
@esbuild/openbsd-x64@0.20.2
@esbuild/sunos-x64@0.20.2
@esbuild/win32-arm64@0.20.2
@esbuild/win32-ia32@0.20.2
@esbuild/win32-x64@0.20.2
@jridgewell/gen-mapping@0.3.5
@jridgewell/resolve-uri@3.1.2
@jridgewell/set-array@1.2.1
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.25
@polka/url@1.0.0-next.25
@rollup/rollup-android-arm-eabi@4.13.2
@rollup/rollup-android-arm64@4.13.2
@rollup/rollup-darwin-arm64@4.13.2
@rollup/rollup-darwin-x64@4.13.2
@rollup/rollup-linux-arm-gnueabihf@4.13.2
@rollup/rollup-linux-arm64-gnu@4.13.2
@rollup/rollup-linux-arm64-musl@4.13.2
@rollup/rollup-linux-powerpc64le-gnu@4.13.2
@rollup/rollup-linux-riscv64-gnu@4.13.2
@rollup/rollup-linux-s390x-gnu@4.13.2
@rollup/rollup-linux-x64-gnu@4.13.2
@rollup/rollup-linux-x64-musl@4.13.2
@rollup/rollup-win32-arm64-msvc@4.13.2
@rollup/rollup-win32-ia32-msvc@4.13.2
@rollup/rollup-win32-x64-msvc@4.13.2
@sveltejs/kit@2.0.4
@sveltejs/vite-plugin-svelte-inspector@2.0.0
@sveltejs/vite-plugin-svelte@3.0.2
@types/cookie@0.6.0
@types/estree@1.0.5
acorn@8.11.3

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
3 Packages, Including:
@ampproject/remapping@2.3.0
aria-query@5.3.0
axobject-query@4.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
picocolors@1.0.0
svelte-hmr@0.15.3

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
mdn-data@2.0.30

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
source-map-js@1.2.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

14
All Dependencies CSV
β“˜ This is a list of @sveltejs/kit 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@sveltejs/vite-plugin-svelte3.0.233.26 kBMIT
prod peer
1
1
@types/cookie0.6.03.45 kBMIT
prod
cookie0.6.07.97 kBMIT
prod
devalue4.3.28.3 kBMIT
prod
esm-env1.0.01.33 kBMIT
prod
kleur4.1.56.01 kBMIT
prod
magic-string0.30.8438.9 kBMIT
prod
mrmime1.0.15.86 kBMIT
prod
sade1.8.110.2 kBMIT
prod
set-cookie-parser2.6.05.71 kBMIT
prod
sirv2.0.46.06 kBMIT
prod
svelte4.2.122.51 MBMIT
prod peer
1
tiny-glob0.2.93.99 kBMIT
prod
vite5.2.73.39 MBMIT
prod peer
1

Visualizations