Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Jan 1, 2024 via pnpm

cote 0.21.1

A Node.js library for building zero-configuration microservices.
Package summary
Share
24
issues
8
critical severity
license
8
6
high severity
vulnerability
2
meta
4
10
moderate severity
vulnerability
4
meta
6
3
licenses
56
MIT
8
N/A
1
ISC
Package created
28 Apr 2013
Version published
29 Sep 2019
Maintainers
1
Total deps
65
Direct deps
10
License
MIT

Issues

24

8 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: socket.io@2.2.0
Recommendation: Check the package code and files for license information
via: socket.io@2.2.0
Recommendation: Check the package code and files for license information
via: socket.io@2.2.0
Recommendation: Check the package code and files for license information
via: socket.io@2.2.0
Recommendation: Check the package code and files for license information
via: @dashersw/axon@2.0.5
Recommendation: Check the package code and files for license information
via: @dashersw/axon@2.0.5
Recommendation: Check the package code and files for license information
via: socket.io@2.2.0
Recommendation: Check the package code and files for license information
via: socket.io@2.2.0
Collapse
Expand

6 high severity issues

high
Recommendation: Upgrade to version 3.1.1 or later
via: @dashersw/node-discover@1.0.5
Recommendation: Upgrade to version 3.6.0 or later
via: socket.io@2.2.0
via: core-js@2.6.12
via: core-js@2.6.12
via: socket.io@2.2.0
via: @dashersw/node-discover@1.0.5 & others
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 3.6.1 or later
via: socket.io@2.2.0
Recommendation: Upgrade to version 6.2.2 or later
via: socket.io@2.2.0
Recommendation: Upgrade to version 2.4.0 or later
via: socket.io@2.2.0
Recommendation: Upgrade to version 4.3.1 or later
via: socket.io@2.2.0
via: socket.io@2.2.0
via: @dashersw/axon@2.0.5
via: @dashersw/axon@2.0.5
via: socket.io@2.2.0
via: socket.io@2.2.0
via: socket.io@2.2.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
56 Packages, Including:
@dashersw/axon@2.0.5
@dashersw/node-discover@1.0.5
accepts@1.3.8
after@0.8.2
amp-message@0.1.2
amp@0.3.1
arraybuffer.slice@0.0.7
async-limiter@1.0.1
async@1.5.2
backo2@1.0.2
base64-arraybuffer@0.1.5
base64id@1.0.0
blob@0.0.5
charm@1.0.2
colors@1.3.3
component-emitter@1.2.1
component-emitter@1.3.1
cookie@0.3.1
core-js@2.6.12
cote@0.21.1
debug@2.6.9
debug@3.1.0
debug@4.1.1
debug@4.3.4
double-ended-queue@2.1.0-0
engine.io-client@3.3.3
engine.io-parser@2.1.3
engine.io@3.3.2
eventemitter2@5.0.1
has-binary2@1.0.3
has-cors@1.1.0
isarray@2.0.1
lodash@4.17.21
mime-db@1.52.0
mime-types@2.1.35
minimist@1.2.8
mkdirp@0.5.6
ms@2.0.0
ms@2.1.2
ms@2.1.3
negotiator@0.6.3
parseqs@0.0.5
parseuri@0.0.5
portfinder@1.0.20
redis-commands@1.7.0
redis-parser@2.6.0
redis@2.8.0
socket.io-adapter@1.1.2
socket.io-client@2.2.0
socket.io-parser@3.3.3

N/A

N/A
8 Packages, Including:
better-assert@1.0.2
callsite@1.0.0
component-bind@1.0.0
component-inherit@0.0.3
configurable@0.0.1
escape-regexp@0.0.1
indexof@0.0.1
object-component@0.0.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
inherits@2.0.4
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

10
All Dependencies CSV
β“˜ This is a list of cote 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@dashersw/axon2.0.512.01 kBMIT
prod
2
2
@dashersw/node-discover1.0.513.56 kBMIT
prod
2
charm1.0.25.18 kBMIT
prod
colors1.3.310.47 kBMIT
prod
core-js2.6.12548.99 kBMIT
prod
2
eventemitter25.0.19.91 kBMIT
prod
lodash4.17.21311.49 kBMIT
prod
portfinder1.0.206.34 kBMIT
prod
socket.io2.2.013.39 kBMIT
prod
6
2
8
uuid3.4.011.87 kBMIT
prod
1

Visualizations