Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 19, 2024 via pnpm

cote 0.15.1

A Node.js library for building zero-configuration microservices.
Package summary
Share
34
issues
13
critical severity
vulnerability
4
license
9
10
high severity
vulnerability
6
meta
4
10
moderate severity
vulnerability
4
meta
6
1
low severity
vulnerability
1
4
licenses
55
MIT
9
N/A
1
ISC
1
Zlib
Package created
28 Apr 2013
Version published
9 Jul 2017
Maintainers
1
Total deps
66
Direct deps
9
License
MIT

Issues

34

13 critical severity issues

critical
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@4.17.4
Recommendation: Upgrade to version 1.6.2 or later
via: socket.io@2.0.3
Recommendation: Upgrade to version 1.6.1 or later
via: socket.io@2.0.3
Recommendation: Upgrade to version 3.3.3 or later
via: socket.io@2.0.3
Recommendation: Check the package code and files for license information
via: @dashersw/node-discover@0.7.1
Recommendation: Check the package code and files for license information
via: socket.io@2.0.3
Recommendation: Check the package code and files for license information
via: socket.io@2.0.3
Recommendation: Check the package code and files for license information
via: socket.io@2.0.3
Recommendation: Check the package code and files for license information
via: socket.io@2.0.3
Recommendation: Check the package code and files for license information
via: @dashersw/axon@2.0.5
Recommendation: Check the package code and files for license information
via: @dashersw/axon@2.0.5
Recommendation: Check the package code and files for license information
via: socket.io@2.0.3
Recommendation: Check the package code and files for license information
via: socket.io@2.0.3
Collapse
Expand

10 high severity issues

high
Recommendation: Upgrade to version 3.1.1 or later
via: @dashersw/node-discover@0.7.1
Recommendation: Upgrade to version 3.6.0 or later
via: socket.io@2.0.3
Recommendation: Upgrade to version 3.3.2 or later
via: socket.io@2.0.3
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@4.17.4
Recommendation: Upgrade to version 4.17.19 or later
via: lodash@4.17.4
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@4.17.4
via: @dashersw/node-discover@0.7.1
via: uuid@3.4.0
via: socket.io@2.0.3
via: socket.io@2.0.3
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@4.17.4
Recommendation: Upgrade to version 3.6.1 or later
via: socket.io@2.0.3
Recommendation: Upgrade to version 2.4.0 or later
via: socket.io@2.0.3
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@4.17.4
via: socket.io@2.0.3
via: @dashersw/axon@2.0.5
via: @dashersw/axon@2.0.5
via: socket.io@2.0.3
via: socket.io@2.0.3
via: socket.io@2.0.3
Collapse
Expand

1 low severity issue

low
Recommendation: Upgrade to version 4.17.5 or later
via: lodash@4.17.4
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
55 Packages, Including:
@dashersw/axon@2.0.5
accepts@1.3.8
after@0.8.2
amp-message@0.1.2
amp@0.3.1
arraybuffer.slice@0.0.7
async-limiter@1.0.1
async@1.5.2
backo2@1.0.2
base64-arraybuffer@0.1.5
base64id@1.0.0
blob@0.0.5
charm@1.0.2
colors@1.1.2
component-emitter@1.2.1
cookie@0.3.1
cote@0.15.1
debug@2.6.9
debug@3.1.0
debug@4.3.4
double-ended-queue@2.1.0-0
engine.io-client@3.1.6
engine.io-parser@2.1.3
engine.io@3.1.5
eventemitter2@4.1.0
has-binary2@1.0.3
has-cors@1.1.0
isarray@2.0.1
lodash@4.17.4
mime-db@1.52.0
mime-types@2.1.35
minimist@1.2.8
mkdirp@0.5.6
ms@2.0.0
ms@2.1.2
negotiator@0.6.3
node-uuid@1.4.8
object-assign@4.1.1
parseqs@0.0.5
parseuri@0.0.5
portfinder@1.0.13
redis-commands@1.7.0
redis-parser@2.6.0
redis@2.8.0
safe-buffer@5.1.2
socket.io-adapter@1.1.2
socket.io-client@2.0.4
socket.io-parser@3.1.3
socket.io@2.0.3
to-array@0.1.4

N/A

N/A
9 Packages, Including:
@dashersw/node-discover@0.7.1
better-assert@1.0.2
callsite@1.0.0
component-bind@1.0.0
component-inherit@0.0.3
configurable@0.0.1
escape-regexp@0.0.1
indexof@0.0.1
object-component@0.0.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
inherits@2.0.4

zlib License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
uws@9.14.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

9
All Dependencies CSV
β“˜ This is a list of cote 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@dashersw/axon2.0.512.01 kBMIT
prod
2
2
@dashersw/node-discover0.7.113.77 kBUNKNOWN
prod
1
2
charm1.0.25.18 kBMIT
prod
colors1.1.28.02 kBMIT
prod
eventemitter24.1.09.59 kBMIT
prod
lodash4.17.4303.39 kBMIT
prod
1
3
2
1
portfinder1.0.135.76 kBMIT
prod
socket.io2.0.319.89 kBMIT
prod
9
4
6
uuid3.4.011.87 kBMIT
prod
1

Visualizations