Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 6, 2024 via pnpm

component 1.1.0

Component package manager consuming git repositories
Package summary
Share
98
issues
20
critical severity
vulnerability
3
license
17
46
high severity
vulnerability
17
license
16
meta
13
16
moderate severity
vulnerability
12
meta
4
16
low severity
vulnerability
1
license
15
13
licenses
160
MIT
18
ISC
17
N/A
31
other licenses
BSD
12
BSD-2-Clause
5
BSD-3-Clause
4
Apache-2.0
3
+ 6 more
Package created
30 Aug 2012
Version published
14 Mar 2015
Maintainers
6
Total deps
226
Direct deps
20
License
UNKNOWN

Issues

98

20 critical severity issues

critical
Recommendation: Upgrade to version 2.2.0 or later
via: component-search2@1.1.1
Recommendation: Upgrade to version 1.1.0 or later
via: component-search2@1.1.1
Recommendation: Upgrade to version 4.2.1 or later
via: component-resolver@1.3.0
Recommendation: Check the package code and files for license information
via: component-search2@1.1.1
Recommendation: Check the package code and files for license information
via: component-build@1.2.2
Recommendation: Check the package code and files for license information
via: component-search2@1.1.1
Recommendation: Check the package code and files for license information
via: component-search2@1.1.1
Recommendation: Check the package code and files for license information
via: component@1.1.0
Recommendation: Check the package code and files for license information
via: superagent@0.17.0
Recommendation: Check the package code and files for license information
via: superagent@0.17.0 & others
Recommendation: Check the package code and files for license information
via: superagent@0.17.0
Recommendation: Check the package code and files for license information
via: component-search2@1.1.1 & others
Recommendation: Check the package code and files for license information
via: superagent@0.17.0
Recommendation: Check the package code and files for license information
via: superagent@0.17.0
Recommendation: Check the package code and files for license information
via: tiny-lr-fork@0.0.5
Recommendation: Check the package code and files for license information
via: tiny-lr-fork@0.0.5
Recommendation: Check the package code and files for license information
via: superagent@0.17.0
Recommendation: Check the package code and files for license information
via: superagent@0.17.0
Recommendation: Check the package code and files for license information
via: component-resolver@1.3.0
Recommendation: Check the package code and files for license information
via: component-watcher@1.0.3
Collapse
Expand

46 high severity issues

high
Recommendation: Upgrade to version 6.0.4 or later
via: superagent@0.17.0 & others
Recommendation: Upgrade to version 3.2.2 or later
via: component-resolver@1.3.0
Recommendation: Upgrade to version 5.0.0 or later
via: component-search2@1.1.1
Recommendation: Upgrade to version 3.0.1 or later
via: component-search2@1.1.1
Recommendation: Upgrade to version 1.0.0 or later
via: superagent@0.17.0 & others
Recommendation: Upgrade to version 2.0.0 or later
via: component-resolver@1.3.0
Recommendation: Upgrade to version 2.1.0 or later
via: component-search2@1.1.1
Recommendation: Upgrade to version 1.0.0 or later
via: superagent@0.17.0 & others
Recommendation: Upgrade to version 4.3.2 or later
via: component-build@1.2.2 & others
Recommendation: Upgrade to version 3.0.2 or later
via: component-build@1.2.2 & others
Recommendation: Upgrade to version 1.4.1 or later
via: superagent@0.17.0
Recommendation: Upgrade to version 2.6.9 or later
via: superagent@0.17.0 & others
Recommendation: Upgrade to version 1.0.12 or later
via: component-resolver@1.3.0
Recommendation: Upgrade to version 4.4.18 or later
via: component-resolver@1.3.0
Recommendation: Upgrade to version 2.2.2 or later
via: component-resolver@1.3.0
Recommendation: Upgrade to version 6.2.4 or later
via: superagent@0.17.0 & others
Recommendation: Upgrade to version 3.0.5 or later
via: component-build@1.2.2 & others
Recommendation: Validate that the package complies with your license policy
via: component-search2@1.1.1
Recommendation: Validate that the package complies with your license policy
via: component-build@1.2.2
Recommendation: Validate that the package complies with your license policy
via: component-resolver@1.3.0
Recommendation: Validate that the package complies with your license policy
via: component-build@1.2.2 & others
Recommendation: Validate that the package complies with your license policy
via: component-build@1.2.2 & others
Recommendation: Validate that the package complies with your license policy
via: component-build@1.2.2
Recommendation: Validate that the package complies with your license policy
via: component-search2@1.1.1
Recommendation: Validate that the package complies with your license policy
via: component-build@1.2.2 & others
Recommendation: Validate that the package complies with your license policy
via: component-build@1.2.2
Recommendation: Validate that the package complies with your license policy
via: component-build@1.2.2
Recommendation: Validate that the package complies with your license policy
via: component-resolver@1.3.0
Recommendation: Validate that the package complies with your license policy
via: win-fork@1.1.1
Recommendation: Validate that the package complies with your license policy
via: component-ls@2.1.0
Recommendation: Read and validate the license terms
via: component-build@1.2.2
Recommendation: Validate that the package complies with your license policy
via: component-search2@1.1.1
Recommendation: Validate that the package complies with your license policy
via: superagent@0.17.0
via: component-build@1.2.2 & others
via: superagent@0.17.0
via: component-build@1.2.2 & others
via: component-build@1.2.2 & others
via: component-build@1.2.2 & others
via: component-build@1.2.2 & others
via: component-resolver@1.3.0
via: component-watcher@1.0.3
via: component-search2@1.1.1
via: component-search2@1.1.1
via: superagent@0.17.0
via: component-resolver@1.3.0
via: component-resolver@1.3.0
Collapse
Expand

16 moderate severity issues

moderate
Recommendation: Upgrade to version 3.3.5 or later
via: component-resolver@1.3.0
Recommendation: Upgrade to version 2.0.2 or later
via: component-search2@1.1.1 & others
Recommendation: Upgrade to version 2.1.4 or later
via: superagent@0.17.0
Recommendation: Upgrade to version 11.8.5 or later
via: component-resolver@1.3.0
Recommendation: Upgrade to version 2.1.0 or later
via: component-search2@1.1.1
Recommendation: Upgrade to version 7.0.36 or later
via: component-build@1.2.2
Recommendation: Upgrade to version 2.0.1 or later
via: component-search2@1.1.1
Recommendation: Upgrade to version 3.7.0 or later
via: superagent@0.17.0
Recommendation: None
via: component-build@1.2.2 & others
Recommendation: Upgrade to version 2.2.3 or later
via: component-search2@1.1.1
Recommendation: Upgrade to version 8.4.31 or later
via: component-build@1.2.2
Recommendation: Upgrade to version 5.7.2 or later
via: component-build@1.2.2 & others
via: superagent@0.17.0
via: superagent@0.17.0
via: tiny-lr-fork@0.0.5
via: superagent@0.17.0
Collapse
Expand

16 low severity issues

low
Recommendation: Upgrade to version 2.6.9 or later
via: superagent@0.17.0 & others
Recommendation: Read and validate the license terms
via: component-search2@1.1.1
Recommendation: Read and validate the license terms
via: component-build@1.2.2
Recommendation: Read and validate the license terms
via: component-resolver@1.3.0
Recommendation: Read and validate the license terms
via: component-build@1.2.2 & others
Recommendation: Read and validate the license terms
via: component-build@1.2.2 & others
Recommendation: Read and validate the license terms
via: component-build@1.2.2
Recommendation: Read and validate the license terms
via: component-search2@1.1.1
Recommendation: Read and validate the license terms
via: component-build@1.2.2 & others
Recommendation: Read and validate the license terms
via: component-build@1.2.2
Recommendation: Read and validate the license terms
via: component-build@1.2.2
Recommendation: Read and validate the license terms
via: component-resolver@1.3.0
Recommendation: Read and validate the license terms
via: win-fork@1.1.1
Recommendation: Read and validate the license terms
via: component-ls@2.1.0
Recommendation: Read and validate the license terms
via: component-build@1.2.2
Recommendation: Read and validate the license terms
via: superagent@0.17.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
160 Packages, Including:
@types/keyv@3.1.4
@types/node@20.12.5
@types/responselike@1.0.3
acorn-walk@7.2.0
acorn@5.7.4
acorn@7.4.1
adm-zip@0.4.16
agent-base@1.0.2
align-text@0.1.4
alter@0.2.0
ast-traverse@0.1.1
ast-types@0.14.2
ast-types@0.8.12
ast-types@0.9.6
autoprefixer-core@3.1.2
balanced-match@1.0.2
brace-expansion@1.1.11
breakable@1.0.0
builder-autoprefixer@1.0.4
builder-es6-module-to-cjs@1.1.0
camelcase@1.2.1
center-align@0.1.3
chanel@2.2.0
co@3.0.6
co@3.1.0
cogent@0.4.3
commander@2.20.3
commoner@0.10.8
component-build@1.2.2
component-builder@1.2.1
component-consoler@2.0.0
component-downloader@1.2.0
component-flatten@1.0.1
component-ls@2.1.0
component-manifest@1.0.0
component-outdated2@1.0.5
component-pin@1.0.5
component-remotes@1.2.0
component-require2@1.1.1
component-resolver@1.3.0
component-search2@1.1.1
component-updater@1.0.5
component-validator@1.1.1
component-watcher@1.0.3
concat-map@0.0.1
core-util-is@1.0.3
cp@0.1.1
data-uri-to-buffer@0.0.4
debug@2.6.9
debug@4.3.4

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
18 Packages, Including:
abbrev@1.1.1
block-stream@0.0.9
cliui@2.1.0
fs.realpath@1.0.0
glob@5.0.15
glob@7.2.3
graceful-fs@3.0.12
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
lru-cache@2.7.3
minimatch@3.1.2
natives@1.1.6
once@1.4.0
rimraf@2.7.1
sigmund@1.0.1
wrappy@1.0.2
y18n@3.2.2

N/A

N/A
17 Packages, Including:
JSONStream@0.8.4
base62@0.1.1
bytes@0.3.0
bytes@1.0.0
component@1.1.0
cookiejar@1.3.0
debug@0.7.4
emitter-component@1.0.0
extend@1.2.1
formidable@1.0.14
mime@1.2.5
noptify@0.0.3
qs@0.5.6
qs@0.6.5
superagent@0.17.0
uuid@1.4.2
watch@0.10.0

BSD

Invalid
Not OSI Approved
12 Packages, Including:
esprima-fb@15001.1001.0-dev-harmony-fb
esprima-fb@3001.1.0-dev-harmony-fb
fstream@0.1.31
glob@3.2.11
graceful-fs@2.0.3
js-base64@2.1.9
regenerator@0.8.46
semver@2.3.2
source-map@0.1.31
source-map@0.1.43
tar@0.1.20
win-fork@1.1.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
escodegen@1.14.3
esprima@3.1.3
esprima@4.0.1
estraverse@4.3.0
esutils@2.0.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
4 Packages, Including:
makeerror@1.0.12
source-map@0.5.7
source-map@0.6.1
tmpl@1.0.5

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
3 Packages, Including:
acorn-node@1.8.2
jstransform@3.0.0
walker@1.0.8

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
archy@0.0.2
wordwrap@0.0.2

BSD-3-Clause OR MIT

Permissive
1 Packages, Including:
amdefine@1.0.1

Creative Commons Attribution 4.0 International

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
caniuse-db@1.0.30001606

(MIT OR Apache2)

Invalid
1 Packages, Including:
pause-stream@0.0.11

Apache, Version 2.0

Invalid
Not OSI Approved
1 Packages, Including:
reduce-component@1.0.1

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
1 Packages, Including:
tslib@2.6.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

20
All Dependencies CSV
β“˜ This is a list of component 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
co3.1.04.42 kBMIT
prod
commander2.20.318.26 kBMIT
prod
component-build1.2.29.98 kBMIT
prod
1
16
4
8
component-consoler2.0.02.44 kBMIT
prod
component-flatten1.0.12.52 kBMIT
prod
3
2
1
component-ls2.1.01.88 kBMIT
prod
1
1
component-outdated21.0.52.31 kBMIT
prod
5
2
2
component-pin1.0.57.83 kBMIT
prod
5
2
2
component-remotes1.2.023.26 kBMIT
prod
4
1
2
component-resolver1.3.020.17 kBMIT
prod
2
21
4
5
component-search21.1.18.23 kBMIT
prod
6
9
4
2
component-updater1.0.56.61 kBMIT
prod
5
2
2
component-watcher1.0.32.99 kBMIT
prod
1
4
debug4.3.412.94 kBMIT
prod
mkdirp0.3.54.06 kBMIT
prod
1
rimraf2.7.15.53 kBISC
prod
semver2.3.232.4 kBBSD
prod
2
1
1
superagent0.17.028.57 kBUNKNOWN
prod
8
9
6
2
tiny-lr-fork0.0.518.07 kBMIT
prod
3
5
1
1
win-fork1.1.12.08 kBBSD
prod
1
1

Visualizations