Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
This package has been deprecated with the following message: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.
Generated on May 7, 2024 via pnpm

botpress 10.51.10

The world's first CMS for bots. Easily create, manage and extend chatbots.
Package summary
Share
98
issues
19
critical severity
vulnerability
5
license
14
48
high severity
vulnerability
13
license
5
meta
30
25
moderate severity
vulnerability
18
meta
7
6
low severity
vulnerability
4
license
2
14
licenses
572
MIT
54
ISC
21
BSD-3-Clause
38
other licenses
N/A
14
Apache-2.0
9
BSD-2-Clause
6
AGPL-3.0-only
2
+ 7 more
Package created
16 Nov 2016
Version published
19 Jan 2019
Maintainers
5
Total deps
685
Direct deps
57
License
AGPL-3.0-only

Issues

98

19 critical severity issues

critical
Recommendation: Upgrade to version 0.19.5 or later
via: knex@0.12.9
Recommendation: None
via: vm2@3.9.19
Recommendation: None
via: vm2@3.9.19
Recommendation: Upgrade to version 1.2.6 or later
via: knex@0.12.9
Recommendation: Upgrade to version 3.3.3 or later
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@2.5.0 & others
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@2.5.0 & others
Recommendation: Check the package code and files for license information
via: prompt@1.3.0 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@2.5.0 & others
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: tamper@1.1.0
Recommendation: Check the package code and files for license information
via: valid-url@1.0.9
Collapse
Expand

48 high severity issues

high
Recommendation: Upgrade to version 3.6.0 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 3.3.2 or later
via: socket.io@1.7.4
Recommendation: None
via: socket.io@1.7.4
Recommendation: Upgrade to version 0.18.1 or later
via: axios@0.15.3
Recommendation: None
via: multer@1.4.4
Recommendation: Upgrade to version 4.2.1 or later
via: jsonwebtoken@7.4.3
Recommendation: Upgrade to version 2.4.0 or later
via: knex@0.12.9
Recommendation: Upgrade to version 2.6.9 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 0.21.2 or later
via: axios@0.15.3
Recommendation: Upgrade to version 5.1.2 or later
via: knex@0.12.9 & others
Recommendation: Upgrade to version 1.14.7 or later
via: axios@0.15.3
Recommendation: Upgrade to version 2.6.7 or later
via: react-toastify@3.4.3
Recommendation: None
via: joi@13.7.0 & others
Recommendation: Validate that the package complies with your license policy
via: @botpress/util-roles@10.51.10
Recommendation: Validate that the package complies with your license policy
via: botpress@10.51.10
Recommendation: Validate that the license expression complies with your license policy
via: nodemon@1.19.4 & others
Recommendation: Validate that the package complies with your license policy
via: prompt@1.3.0
Recommendation: Validate that the package complies with your license policy
via: pg@6.4.2
via: @botpress/util-roles@10.51.10
via: axios@0.15.3
via: botpress@10.51.10
via: nodemon@1.19.4
via: react-toastify@3.4.3
via: babel-polyfill@6.26.0 & others
via: babel-polyfill@6.26.0 & others
via: nodemon@1.19.4
via: nodemon@1.19.4
via: universal-analytics@0.4.23
via: jsonwebtoken@7.4.3
via: joi@13.7.0
via: joi@13.7.0
via: joi@13.7.0
via: jsonwebtoken@7.4.3
via: socket.io@1.7.4
via: monitorctrlc@2.0.1
via: multer@1.4.4
via: sqlite3@4.2.0
via: nodemon@1.19.4
via: react-jsonschema-form@1.8.1
via: universal-analytics@0.4.23
via: nodemon@1.19.4
via: nodemon@1.19.4
via: nodemon@1.19.4
via: sqlite3@4.2.0
via: jsonwebtoken@7.4.3
via: joi@13.7.0
via: nodemon@1.19.4
via: knex@0.12.9 & others
Collapse
Expand

25 moderate severity issues

moderate
Recommendation: Upgrade to version 4.0.0 or later
via: username@3.0.0
Recommendation: Upgrade to version 11.8.5 or later
via: nodemon@1.19.4
Recommendation: Upgrade to version 9.0.0 or later
via: jsonwebtoken@7.4.3 & others
Recommendation: Upgrade to version 3.6.1 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 0.21.1 or later
via: axios@0.15.3
Recommendation: Upgrade to version 9.0.0 or later
via: jsonwebtoken@7.4.3 & others
Recommendation: Upgrade to version 9.0.0 or later
via: jsonwebtoken@7.4.3 & others
Recommendation: Upgrade to version 1.14.8 or later
via: axios@0.15.3
Recommendation: Upgrade to version 2.4.0 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 2.0.0 or later
via: ms@0.7.3 & others
Recommendation: Upgrade to version 1.15.4 or later
via: axios@0.15.3
Recommendation: Upgrade to version 1.2.3 or later
via: knex@0.12.9
Recommendation: Upgrade to version 5.7.2 or later
via: pg@6.4.2
Recommendation: Upgrade to version 0.28.0 or later
via: axios@0.15.3
Recommendation: Upgrade to version 4.1.3 or later
via: universal-analytics@0.4.23
Recommendation: None
via: universal-analytics@0.4.23
Recommendation: Upgrade to version 1.15.6 or later
via: axios@0.15.3
Recommendation: Upgrade to version 6.2.1 or later
via: sqlite3@4.2.0
via: @botpress/util-roles@10.51.10
via: socket.io@1.7.4
via: prompt@1.3.0 & others
via: socket.io-client@2.5.0
via: socket.io@1.7.4
via: socket.io-client@2.5.0 & others
via: socket.io@1.7.4
Collapse
Expand

6 low severity issues

low
Recommendation: Upgrade to version 2.3.1 or later
via: knex@0.12.9
Recommendation: Upgrade to version 2.3.1 or later
via: knex@0.12.9
Recommendation: Upgrade to version 2.6.1 or later
via: react-toastify@3.4.3
Recommendation: Upgrade to version 2.6.9 or later
via: socket.io@1.7.4
Recommendation: Read and validate the license terms
via: prompt@1.3.0
Recommendation: Read and validate the license terms
via: pg@6.4.2
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
572 Packages, Including:
@babel/runtime-corejs2@7.24.5
@babel/runtime@7.24.5
@colors/colors@1.5.0
@types/keyv@3.1.4
@types/node@20.12.10
@types/responselike@1.0.3
accepts@1.3.3
accepts@1.3.8
acorn-walk@8.3.2
acorn@8.11.3
after@0.8.2
ajv@6.12.6
ansi-bgblack@0.1.1
ansi-bgblue@0.1.1
ansi-bgcyan@0.1.1
ansi-bggreen@0.1.1
ansi-bgmagenta@0.1.1
ansi-bgred@0.1.1
ansi-bgwhite@0.1.1
ansi-bgyellow@0.1.1
ansi-black@0.1.1
ansi-blue@0.1.1
ansi-bold@0.1.1
ansi-colors@0.2.0
ansi-cyan@0.1.1
ansi-dim@0.1.1
ansi-gray@0.1.1
ansi-green@0.1.1
ansi-grey@0.1.1
ansi-hidden@0.1.1
ansi-inverse@0.1.1
ansi-italic@0.1.1
ansi-magenta@0.1.1
ansi-red@0.1.1
ansi-regex@2.1.1
ansi-regex@3.0.1
ansi-reset@0.1.1
ansi-strikethrough@0.1.1
ansi-styles@2.2.1
ansi-styles@3.2.1
ansi-underline@0.1.1
ansi-white@0.1.1
ansi-wrap@0.1.0
ansi-yellow@0.1.1
append-field@1.0.0
argparse@1.0.10
arr-diff@2.0.0
arr-diff@4.0.0
arr-flatten@1.1.0
arr-swap@1.0.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
54 Packages, Including:
abbrev@1.1.1
ansi-align@2.0.0
anymatch@2.0.0
aproba@1.2.0
are-we-there-yet@1.1.7
chownr@1.1.4
console-control-strings@1.1.0
fs-minipass@1.2.7
fs.realpath@1.0.0
gauge@2.7.4
glob-parent@2.0.0
glob-parent@3.1.0
glob@7.2.3
graceful-fs@4.2.11
har-schema@2.0.0
has-unicode@2.0.1
ignore-by-default@1.0.1
ignore-walk@3.0.4
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
isexe@2.0.0
json-stringify-safe@5.0.1
lru-cache@4.1.5
minimatch@3.1.2
minipass@2.9.0
mute-stream@0.0.7
mute-stream@0.0.8
nopt@4.0.3
npm-bundled@1.1.2
npm-normalize-package-bin@1.0.1
npm-packlist@1.4.8
npmlog@4.1.2
once@1.4.0
osenv@0.1.5
pg-int8@1.0.1
pseudomap@1.0.2
read@1.0.7
remove-trailing-separator@1.1.0
rimraf@2.7.1
sax@1.3.0
semver@5.7.2
set-blocking@2.0.0
setprototypeof@1.2.0
signal-exit@3.0.7
split2@4.2.0
tar@4.4.19
touch@3.1.0
which@1.3.1
wide-align@1.1.5

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
21 Packages, Including:
bcrypt-pbkdf@1.0.2
buffer-equal-constant-time@1.0.1
duplexer3@0.1.5
hoek@2.16.3
hoek@5.0.4
hoek@6.1.3
hoist-non-react-statics@2.5.5
hyphenate-style-name@1.0.4
isemail@3.2.0
joi@13.7.0
joi@6.10.1
node-pre-gyp@0.11.0
qs@6.11.0
qs@6.5.3
react-transition-group@2.9.0
source-map@0.5.7
sprintf-js@1.0.3
sqlite3@4.2.0
topo@1.1.0
topo@3.0.3
tough-cookie@2.5.0

N/A

N/A
14 Packages, Including:
arraybuffer.slice@0.0.6
better-assert@1.0.2
blob@0.0.4
callsite@1.0.0
component-bind@1.0.0
component-emitter@1.1.2
component-inherit@0.0.3
cycle@1.0.3
indexof@0.0.1
ms@0.7.1
object-component@0.0.3
options@0.0.6
tamper@1.1.0
valid-url@1.0.9

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
9 Packages, Including:
aws-sign2@0.7.0
caseless@0.12.0
detect-libc@1.0.3
ecdsa-sig-formatter@1.0.11
forever-agent@0.6.1
oauth-sign@0.9.0
react-jsonschema-form@1.8.1
request@2.88.2
tunnel-agent@0.6.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
6 Packages, Including:
configstore@3.1.5
dotenv@4.0.0
esprima@4.0.1
isemail@1.2.0
update-notifier@2.5.0
uri-js@4.4.1

GNU Affero General Public License v3.0 only

Network Protective
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
sublicense
hold-liable
Must
include-copyright
include-license
state-changes
disclose-source
include-install-instructions
2 Packages, Including:
@botpress/util-roles@10.51.10
botpress@10.51.10

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

(WTFPL OR MIT)

Permissive
1 Packages, Including:
path-is-inside@1.0.2

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
revalidator@0.1.8

BSD

Invalid
Not OSI Approved
1 Packages, Including:
semver@4.3.2

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

57
All Dependencies CSV
β“˜ This is a list of botpress 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@botpress/util-roles10.51.106.39 kBAGPL-3.0-only
prod
2
1
axios0.15.374.51 kBMIT
prod
4
5
babel-polyfill6.26.0129.23 kBMIT
prod
2
bluebird3.7.2136.03 kBMIT
prod
body-parser1.20.214.75 kBMIT
prod
chalk2.4.29.63 kBMIT
prod
commander2.20.318.26 kBMIT
prod
compression1.7.47.64 kBMIT
prod
dotenv4.0.05.89 kBBSD-2-Clause
prod
eventemitter22.2.29.09 kBMIT
prod
express4.19.2209.73 kBMIT
prod
glob7.2.315.08 kBISC
prod
history4.10.121.13 kBMIT
prod
howler2.2.471 kBMIT
prod
joi13.7.035.46 kBBSD-3-Clause
prod
5
js-yaml3.14.175.07 kBMIT
prod
json51.0.221.68 kBMIT
prod
jsonwebtoken7.4.386.72 kBMIT
prod
5
3
knex0.12.9168.26 kBMIT
prod
2
5
1
2
loaders.css0.1.220.65 kBMIT
prod
lodash4.17.21311.49 kBMIT
prod
mkdirp0.5.62.95 kBMIT
prod optional
moment2.30.1698.76 kBMIT
prod
monitorctrlc2.0.13.09 kBMIT
prod
1
ms0.7.32.81 kBMIT
prod
1
multer1.4.49.07 kBMIT
prod
2
mustache2.3.222.61 kBMIT
prod
mware0.0.32.61 kBMIT
prod
nanoid1.3.47.27 kBMIT
prod
node-machine-id1.1.1212.76 kBMIT
prod
nodemon1.19.432.94 kBMIT
prod
10
1
opn5.5.09.27 kBMIT
prod
pg6.4.227.26 kBMIT
prod
1
1
1
prepend-file1.3.12.74 kBMIT
prod
prompt-confirm1.2.03.23 kBMIT
prod
prompt1.3.025.04 kBMIT
prod
1
1
1
1
query-string5.1.14.61 kBMIT
prod
randomstring1.3.05.15 kBMIT
prod
react-jsonschema-form1.8.1732.33 kBApache-2.0
prod
3
react-loaders3.0.16.21 kBMIT
prod
react-router-dom4.3.140.48 kBMIT
prod
react-toastify3.4.3178.83 kBMIT
prod
2
1
rimraf2.7.15.53 kBISC
prod optional
semver5.7.217.45 kBISC
prod optional
socket.io-client2.5.0388.33 kBMIT
prod
3
2
socket.io1.7.419.67 kBMIT
prod
12
5
7
1
socketio-jwt4.6.224.46 kBMIT
prod
3
source-map-support0.4.1823.9 kBMIT
prod
sqlite34.2.02.79 MBBSD-3-Clause
prod optional
3
1
tamper1.1.03.65 kBUNKNOWN
prod
1
universal-analytics0.4.2325.02 kBMIT
prod
3
2
username3.0.01.91 kBMIT
prod
1
valid-url1.0.95 kBUNKNOWN
prod
1
verror1.10.111.88 kBMIT
prod
vm23.9.1952.97 kBMIT
prod
2
winston2.4.740.46 kBMIT
prod
1
1
yn2.0.02.37 kBMIT
prod

Visualizations