Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 20, 2024 via pnpm

cote 0.19.0

A Node.js library for building zero-configuration microservices.
Package summary
Share
31
issues
12
critical severity
vulnerability
4
license
8
9
high severity
vulnerability
6
meta
3
10
moderate severity
vulnerability
4
meta
6
3
licenses
55
MIT
8
N/A
1
ISC
Package created
28 Apr 2013
Version published
25 Jan 2019
Maintainers
1
Total deps
64
Direct deps
10
License
MIT

Issues

31

12 critical severity issues

critical
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@4.17.10
Recommendation: Upgrade to version 1.6.2 or later
via: socket.io@2.1.1
Recommendation: Upgrade to version 1.6.1 or later
via: socket.io@2.1.1
Recommendation: Upgrade to version 3.3.3 or later
via: socket.io@2.1.1
Recommendation: Check the package code and files for license information
via: socket.io@2.1.1
Recommendation: Check the package code and files for license information
via: socket.io@2.1.1
Recommendation: Check the package code and files for license information
via: socket.io@2.1.1
Recommendation: Check the package code and files for license information
via: socket.io@2.1.1
Recommendation: Check the package code and files for license information
via: @dashersw/axon@2.0.5
Recommendation: Check the package code and files for license information
via: @dashersw/axon@2.0.5
Recommendation: Check the package code and files for license information
via: socket.io@2.1.1
Recommendation: Check the package code and files for license information
via: socket.io@2.1.1
Collapse
Expand

9 high severity issues

high
Recommendation: Upgrade to version 3.1.1 or later
via: @dashersw/node-discover@1.0.5
Recommendation: Upgrade to version 3.6.0 or later
via: socket.io@2.1.1
Recommendation: Upgrade to version 3.3.2 or later
via: socket.io@2.1.1
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@4.17.10
Recommendation: Upgrade to version 4.17.19 or later
via: lodash@4.17.10
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@4.17.10
via: core-js@2.6.12
via: core-js@2.6.12
via: @dashersw/node-discover@1.0.5 & others
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@4.17.10
Recommendation: Upgrade to version 3.6.1 or later
via: socket.io@2.1.1
Recommendation: Upgrade to version 2.4.0 or later
via: socket.io@2.1.1
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@4.17.10
via: socket.io@2.1.1
via: @dashersw/axon@2.0.5
via: @dashersw/axon@2.0.5
via: socket.io@2.1.1
via: socket.io@2.1.1
via: socket.io@2.1.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
55 Packages, Including:
@dashersw/axon@2.0.5
@dashersw/node-discover@1.0.5
accepts@1.3.8
after@0.8.2
amp-message@0.1.2
amp@0.3.1
arraybuffer.slice@0.0.7
async-limiter@1.0.1
async@1.5.2
backo2@1.0.2
base64-arraybuffer@0.1.5
base64id@1.0.0
blob@0.0.5
charm@1.0.2
colors@1.3.0
component-emitter@1.2.1
cookie@0.3.1
core-js@2.6.12
cote@0.19.0
debug@2.6.9
debug@3.1.0
debug@4.3.4
double-ended-queue@2.1.0-0
engine.io-client@3.2.1
engine.io-parser@2.1.3
engine.io@3.2.1
eventemitter2@5.0.1
has-binary2@1.0.3
has-cors@1.1.0
isarray@2.0.1
lodash@4.17.10
mime-db@1.52.0
mime-types@2.1.35
minimist@1.2.8
mkdirp@0.5.6
ms@2.0.0
ms@2.1.2
negotiator@0.6.3
parseqs@0.0.5
parseuri@0.0.5
portfinder@1.0.13
redis-commands@1.7.0
redis-parser@2.6.0
redis@2.8.0
safe-buffer@5.1.2
socket.io-adapter@1.1.2
socket.io-client@2.1.1
socket.io-parser@3.2.0
socket.io@2.1.1
to-array@0.1.4

N/A

N/A
8 Packages, Including:
better-assert@1.0.2
callsite@1.0.0
component-bind@1.0.0
component-inherit@0.0.3
configurable@0.0.1
escape-regexp@0.0.1
indexof@0.0.1
object-component@0.0.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
inherits@2.0.4
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

10
All Dependencies CSV
β“˜ This is a list of cote 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@dashersw/axon2.0.512.01 kBMIT
prod
2
2
@dashersw/node-discover1.0.513.56 kBMIT
prod
2
charm1.0.25.18 kBMIT
prod
colors1.3.010.38 kBMIT
prod
core-js2.6.12548.99 kBMIT
prod
2
eventemitter25.0.19.91 kBMIT
prod
lodash4.17.10298.5 kBMIT
prod
1
3
2
portfinder1.0.135.76 kBMIT
prod
socket.io2.1.113.36 kBMIT
prod
9
2
6
uuid3.4.011.87 kBMIT
prod
1

Visualizations