Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 8, 2024 via pnpm
Package summary
Share
6
issues
3
critical severity
license
3
1
high severity
license
1
2
low severity
license
2
8
licenses
50
MIT
5
ISC
3
N/A
8
other licenses
BSD-2-Clause
3
Apache-2.0
2
CC-BY-3.0
1
CC0-1.0
1
+ 1 more
Package created
3 Dec 2022
Version published
31 May 2023
Maintainers
1
Total deps
66
Direct deps
9
License
MIT

Issues

6

3 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: conf@11.0.2
Recommendation: Check the package code and files for license information
via: conf@11.0.2
Recommendation: Check the package code and files for license information
via: conf@11.0.2
Collapse
Expand

1 high severity issue

high
Recommendation: Read and validate the license terms
via: read-pkg-up@9.1.0
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: read-pkg-up@9.1.0
Recommendation: Read and validate the license terms
via: read-pkg-up@9.1.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
50 Packages, Including:
@babel/code-frame@7.24.2
@babel/helper-validator-identifier@7.24.5
@babel/highlight@7.24.5
@types/normalize-package-data@2.4.4
ajv-formats@2.1.1
ajv@8.13.0
ansi-styles@3.2.1
base64-js@1.5.1
cac@6.7.14
chalk@2.4.2
chatgpt@5.2.5
color-convert@1.9.3
color-name@1.1.3
conf@11.0.2
debounce-fn@5.1.2
dot-prop@7.2.0
env-paths@3.0.0
error-ex@1.3.2
escape-string-regexp@1.0.5
eventsource-parser@1.1.2
fast-deep-equal@3.1.3
find-up@6.3.0
function-bind@1.1.2
has-flag@3.0.0
hasown@2.0.2
is-arrayish@0.2.1
is-core-module@2.13.1
js-tiktoken@1.0.11
js-tokens@4.0.0
json-buffer@3.0.1
json-parse-even-better-errors@2.3.1
json-schema-traverse@1.0.0
keyv@4.5.4
lines-and-columns@1.2.4
locate-path@7.2.0
mimic-fn@4.0.0
p-limit@4.0.0
p-locate@6.0.0
p-timeout@6.1.2
parse-json@5.2.0
path-exists@5.0.0
punycode@2.3.1
quick-lru@6.1.2
read-pkg-up@9.1.0
read-pkg@7.1.0
require-from-string@2.0.2
spdx-expression-parse@3.0.1
supports-color@5.5.0
uuid@9.0.1
yocto-queue@1.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
hosted-git-info@4.1.0
lru-cache@6.0.0
picocolors@1.0.0
semver@7.6.1
yallist@4.0.0

N/A

N/A
3 Packages, Including:
atomically@2.0.3
stubborn-fs@1.2.5
when-exit@2.1.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
json-schema-typed@8.0.1
normalize-package-data@3.0.3
uri-js@4.4.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
spdx-correct@3.2.0
validate-npm-package-license@3.0.4

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17

(MIT OR CC0-1.0)

Public Domain
1 Packages, Including:
type-fest@2.19.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

9
All Dependencies CSV
β“˜ This is a list of chatgpt 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
cac6.7.1421.41 kBMIT
prod
conf11.0.211.78 kBMIT
prod
3
eventsource-parser1.1.2198.83 kBMIT
prod
js-tiktoken1.0.116.27 MBMIT
prod
keyv4.5.48.42 kBMIT
prod
p-timeout6.1.23.81 kBMIT
prod
quick-lru6.1.24.66 kBMIT
prod
read-pkg-up9.1.02.53 kBMIT
prod
1
2
uuid9.0.122.94 kBMIT
prod

Visualizations