Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 28, 2024 via pnpm

ai 2.2.12

The Vercel AI SDK is **a library for building AI-powered streaming text and chat UIs**.
Package summary
Share
2
issues
1
moderate severity
meta
1
1
low severity
license
1
6
licenses
72
MIT
6
Apache-2.0
4
BSD-3-Clause
5
other licenses
ISC
2
BSD-2-Clause
2
CC0-1.0
1
Package created
21 Feb 2014
Version published
7 Sep 2023
Maintainers
11
Total deps
87
Direct deps
12
License
Apache-2.0

Issues

2

1 moderate severity issue

moderate
via: sswr@2.0.0
Collapse
Expand

1 low severity issue

low
Recommendation: Read and validate the license terms
via: sswr@2.0.0 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
72 Packages, Including:
@babel/helper-string-parser@7.24.1
@babel/helper-validator-identifier@7.22.20
@babel/parser@7.24.1
@babel/types@7.24.0
@jridgewell/gen-mapping@0.3.5
@jridgewell/resolve-uri@3.1.2
@jridgewell/set-array@1.2.1
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.25
@types/estree@1.0.5
@types/node-fetch@2.6.11
@types/node@18.19.26
@vue/compiler-core@3.4.21
@vue/compiler-dom@3.4.21
@vue/compiler-sfc@3.4.21
@vue/compiler-ssr@3.4.21
@vue/reactivity@3.4.21
@vue/runtime-core@3.4.21
@vue/runtime-dom@3.4.21
@vue/server-renderer@3.4.21
@vue/shared@3.4.21
abort-controller@3.0.0
acorn@8.11.3
agentkeepalive@4.5.0
asynckit@0.4.0
base-64@0.1.0
code-red@1.0.4
combined-stream@1.0.8
css-tree@2.3.1
csstype@3.1.3
delayed-stream@1.0.0
dequal@2.0.3
estree-walker@2.0.2
estree-walker@3.0.3
event-target-shim@5.0.1
eventsource-parser@1.0.0
form-data-encoder@1.7.2
form-data@4.0.0
formdata-node@4.4.1
humanize-ms@1.2.1
is-buffer@1.1.6
is-reference@3.0.2
js-tokens@4.0.0
locate-character@3.0.0
loose-envify@1.4.0
magic-string@0.30.8
mime-db@1.52.0
mime-types@2.1.35
ms@2.1.3
nanoid@3.3.6

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
6 Packages, Including:
@ampproject/remapping@2.3.0
ai@2.2.12
aria-query@5.3.0
axobject-query@4.0.0
openai@4.2.0
swrv@1.0.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
4 Packages, Including:
charenc@0.0.2
crypt@0.0.2
md5@2.3.0
source-map-js@1.2.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
digest-fetch@1.3.0
picocolors@1.0.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
entities@4.5.0
webidl-conversions@3.0.1

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
mdn-data@2.0.30
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

12
All Dependencies CSV
β“˜ This is a list of ai 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
eventsource-parser1.0.014.22 kBMIT
prod
nanoid3.3.65.32 kBMIT
prod
openai4.2.0136.72 kBApache-2.0
prod
react18.2.079.25 kBMIT
prod peer
solid-js1.8.16832.95 kBMIT
prod peer
solid-swr-store0.10.75.11 kBMIT
prod
sswr2.0.08.97 kBMIT
prod
1
1
svelte4.2.122.51 MBMIT
prod peer
1
swr-store0.10.623.7 kBMIT
prod peer
swr2.2.062.37 kBMIT
prod
swrv1.0.41 BApache-2.0
prod
vue3.4.212.09 MBMIT
prod peer

Visualizations