Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 31, 2024 via pnpm

bottender 1.1.2

A framework for building conversational user interfaces.
Package summary
Share
42
issues
1
critical severity
license
1
28
high severity
vulnerability
4
license
4
meta
20
10
moderate severity
vulnerability
8
meta
2
3
low severity
license
3
15
licenses
528
MIT
36
ISC
13
Apache-2.0
34
other licenses
BSD-3-Clause
11
BSD-2-Clause
8
(MIT OR CC0-1.0)
4
MIT/X11
2
+ 8 more
Package created
4 Aug 2017
Version published
3 Jan 2020
Maintainers
6
Total deps
611
Direct deps
48
License
MIT

Issues

42

1 critical severity issue

critical
Recommendation: Check the package code and files for license information
via: ngrok@3.4.1
Collapse
Expand

28 high severity issues

high
Recommendation: Upgrade to version 0.21.2 or later
via: axios@0.19.2
Recommendation: Upgrade to version 5.1.2 or later
via: nodemon@1.19.4
Recommendation: Upgrade to version 1.14.7 or later
via: axios@0.19.2
Recommendation: Upgrade to version 2.6.4 or later
via: jfs@0.3.0
Recommendation: Validate that the package complies with your license policy
via: ngrok@3.4.1
Recommendation: Validate that the package complies with your license policy
via: ngrok@3.4.1
Recommendation: Validate that the license expression complies with your license policy
via: nodemon@1.19.4 & others
Recommendation: Validate that the package complies with your license policy
via: readline@1.3.0
via: @hapi/joi@15.1.1
via: @hapi/joi@15.1.1
via: @hapi/joi@15.1.1
via: @hapi/joi@15.1.1
via: @hapi/joi@15.1.1
via: @bottender/express@1.5.1
via: axios@0.19.2
via: nodemon@1.19.4
via: nodemon@1.19.4
via: nodemon@1.19.4
via: ngrok@3.4.1
via: ngrok@3.4.1
via: nodemon@1.19.4
via: ngrok@3.4.1
via: ngrok@3.4.1
via: nodemon@1.19.4
via: nodemon@1.19.4
via: nodemon@1.19.4
via: nodemon@1.19.4
via: jfs@0.3.0 & others
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 11.8.5 or later
via: nodemon@1.19.4 & others
Recommendation: Upgrade to version 0.21.1 or later
via: axios@0.19.2
Recommendation: Upgrade to version 1.14.8 or later
via: axios@0.19.2
Recommendation: Upgrade to version 1.15.4 or later
via: axios@0.19.2
Recommendation: Upgrade to version 0.28.0 or later
via: @slack/rtm-api@5.0.5 & others
Recommendation: Upgrade to version 4.1.3 or later
via: ngrok@3.4.1
Recommendation: None
via: ngrok@3.4.1
Recommendation: Upgrade to version 1.15.6 or later
via: axios@0.19.2
via: @bottender/express@1.5.1
via: messenger-batch@0.3.1
Collapse
Expand

3 low severity issues

low
Recommendation: Read and validate the license terms
via: ngrok@3.4.1
Recommendation: Read and validate the license terms
via: ngrok@3.4.1
Recommendation: Read and validate the license terms
via: readline@1.3.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
528 Packages, Including:
@babel/runtime@7.24.1
@bottender/express@1.5.1
@sindresorhus/is@0.14.0
@slack/logger@2.0.0
@slack/rtm-api@5.0.5
@slack/types@1.10.0
@slack/web-api@5.15.0
@szmarczak/http-timer@1.1.2
@types/append-query@2.0.3
@types/body-parser@1.19.5
@types/caseless@0.12.5
@types/connect@3.4.38
@types/debug@4.1.12
@types/express-serve-static-core@4.17.43
@types/express@4.17.21
@types/http-errors@2.0.4
@types/is-stream@1.1.0
@types/keyv@3.1.4
@types/lodash@4.17.0
@types/mime@1.3.5
@types/mime@4.0.0
@types/ms@0.7.34
@types/node@20.12.2
@types/node@8.10.66
@types/p-queue@2.3.2
@types/qs@6.9.14
@types/range-parser@1.2.7
@types/request@2.48.12
@types/responselike@1.0.3
@types/retry@0.12.0
@types/send@0.17.4
@types/serve-static@1.15.5
@types/tough-cookie@4.0.5
@types/url-join@4.0.3
@types/warning@3.0.3
@types/ws@7.4.7
accepts@1.3.8
aggregate-error@3.1.0
ajv@6.12.6
ansi-bgblack@0.1.1
ansi-bgblue@0.1.1
ansi-bgcyan@0.1.1
ansi-bggreen@0.1.1
ansi-bgmagenta@0.1.1
ansi-bgred@0.1.1
ansi-bgwhite@0.1.1
ansi-bgyellow@0.1.1
ansi-black@0.1.1
ansi-blue@0.1.1
ansi-bold@0.1.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
36 Packages, Including:
abbrev@1.1.1
ansi-align@2.0.0
ansi-align@3.0.1
anymatch@2.0.0
cli-width@3.0.0
glob-parent@3.1.0
graceful-fs@4.2.11
har-schema@2.0.0
ignore-by-default@1.0.1
inherits@2.0.4
ini@1.3.8
isexe@2.0.0
json-stringify-safe@5.0.1
lru-cache@4.1.5
lru-cache@5.1.1
minimatch@3.1.2
mute-stream@0.0.7
mute-stream@0.0.8
nopt@3.0.6
once@1.4.0
pseudomap@1.0.2
remove-trailing-separator@1.1.0
request-promise-core@1.1.4
request-promise-native@1.0.9
semver@5.7.2
semver@6.3.1
setprototypeof@1.2.0
signal-exit@3.0.7
stealthy-require@1.1.1
touch@0.0.3
touch@3.1.0
which@1.3.1
wrappy@1.0.2
write-file-atomic@2.4.3
yallist@2.1.2
yallist@3.1.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
13 Packages, Including:
aws-sign2@0.7.0
bson@1.1.6
caseless@0.12.0
cluster-key-slot@1.1.2
denque@1.5.1
forever-agent@0.6.1
mongodb@3.7.4
oauth-sign@0.9.0
optional-require@1.1.8
request@2.88.2
require-at@1.0.6
rxjs@6.6.7
tunnel-agent@0.6.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
11 Packages, Including:
@hapi/address@2.1.4
@hapi/bourne@1.3.2
@hapi/hoek@8.5.1
@hapi/joi@15.1.1
@hapi/topo@3.1.6
bcrypt-pbkdf@1.0.2
duplexer3@0.1.5
qs@6.11.0
qs@6.5.3
source-map@0.5.7
tough-cookie@2.5.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
8 Packages, Including:
configstore@3.1.5
configstore@4.0.0
dotenv@8.6.0
http-cache-semantics@4.1.1
ngrok@3.4.1
update-notifier@2.5.0
update-notifier@3.0.1
uri-js@4.4.1

(MIT OR CC0-1.0)

Public Domain
4 Packages, Including:
type-fest@0.15.1
type-fest@0.21.3
type-fest@0.3.1
type-fest@0.8.1

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
chainsaw@0.1.0
traverse@0.3.9

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

N/A

N/A
1 Packages, Including:
buffers@0.1.1

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

(WTFPL OR MIT)

Permissive
1 Packages, Including:
path-is-inside@1.0.2

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

BSD

Invalid
Not OSI Approved
1 Packages, Including:
readline@1.3.0

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

48
All Dependencies CSV
β“˜ This is a list of bottender 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@bottender/express1.5.14.26 kBMIT
prod
1
1
@hapi/joi15.1.137.32 kBBSD-3-Clause
prod
5
@slack/rtm-api5.0.524.98 kBMIT
prod
1
arg4.1.35.23 kBMIT
prod
axios0.19.285.88 kBMIT
prod
3
5
chalk2.4.29.63 kBMIT
prod
cli-table30.5.112.28 kBMIT
prod
date-fns2.30.0682.42 kBMIT
prod
debug4.3.412.94 kBMIT
prod
deep-object-diff1.1.94.74 kBMIT
prod
delay4.4.13.96 kBMIT
prod
dotenv8.6.08.9 kBBSD-2-Clause
prod
express4.19.2209.73 kBMIT
prod
figures3.2.04.19 kBMIT
prod
file-type12.4.214.51 kBMIT
prod
fromentries1.3.22.44 kBMIT
prod
fs-extra8.1.031.77 kBMIT
prod
hasha5.2.24.81 kBMIT
prod
import-fresh3.3.02.28 kBMIT
prod
inquirer7.3.322.32 kBMIT
prod
invariant2.2.43.01 kBMIT
prod
ioredis4.28.579.48 kBMIT
prod
jfs0.3.09.13 kBMIT
prod
2
jsonfile5.0.05.39 kBMIT
prod
lodash4.17.21311.49 kBMIT
prod
lru-cache5.1.15.69 kBISC
prod
messaging-api-common1.0.415.62 kBMIT
prod
1
messaging-api-line1.1.0183.19 kBMIT
prod
1
messaging-api-messenger1.1.0104.34 kBMIT
prod
1
messaging-api-slack1.1.041.05 kBMIT
prod
1
messaging-api-telegram1.1.086.58 kBMIT
prod
1
messaging-api-viber1.1.036.01 kBMIT
prod
1
messenger-batch0.3.15.5 kBMIT
prod
1
minimist1.2.815.16 kBMIT
prod
mongodb3.7.4287.9 kBApache-2.0
prod
ngrok3.4.112.89 MBBSD-2-Clause
prod
1
7
2
2
nodemon1.19.432.94 kBMIT
prod
10
1
p-map3.0.03.26 kBMIT
prod
p-props3.1.02.67 kBMIT
prod
pascal-case2.0.12.06 kBMIT
prod
pkg-dir4.2.02.07 kBMIT
prod
prompt-confirm2.0.43.57 kBMIT
prod
read-chunk3.2.02.02 kBMIT
prod
readline1.3.0719.36 kBBSD
prod
1
1
recursive-readdir2.2.32.42 kBMIT
prod
shortid2.2.168.45 kBMIT
prod
update-notifier3.0.15.89 kBBSD-2-Clause
prod
1
1
warning4.0.33.66 kBMIT
prod

Visualizations