Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 28, 2024 via pnpm
Package summary
Share
9
issues
1
critical severity
vulnerability
1
5
high severity
vulnerability
4
meta
1
2
moderate severity
vulnerability
2
1
low severity
vulnerability
1
2
licenses
13
MIT
1
ISC
Package created
6 May 2016
Version published
3 Jan 2019
Maintainers
6
Total deps
14
Direct deps
7
License
ISC

Issues

9

1 critical severity issue

critical
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@4.17.10 & others
Collapse
Expand

5 high severity issues

high
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@4.17.10 & others
Recommendation: Upgrade to version 2.6.7 or later
via: isomorphic-fetch@2.2.1
Recommendation: Upgrade to version 4.17.19 or later
via: lodash@4.17.10 & others
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@4.17.10 & others
via: uuid@3.0.1
Collapse
Expand

2 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@4.17.10 & others
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@4.17.10 & others
Collapse
Expand

1 low severity issue

low
Recommendation: Upgrade to version 2.6.1 or later
via: isomorphic-fetch@2.2.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
13 Packages, Including:
encoding@0.1.13
es6-promise@4.1.0
iconv-lite@0.6.3
is-stream@1.1.0
isomorphic-fetch@2.2.1
lodash@4.17.10
meld@1.3.2
node-fetch@1.7.3
redact-pii@1.3.1
safer-buffer@2.1.2
traverse@0.6.6
uuid@3.0.1
whatwg-fetch@3.6.20

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
dashbot@10.2.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

7
All Dependencies CSV
β“˜ This is a list of dashbot 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
es6-promise4.1.073.15 kBMIT
prod
isomorphic-fetch2.2.13.23 kBMIT
prod
1
1
lodash4.17.10298.5 kBMIT
prod
1
3
2
meld1.3.29.07 kBMIT
prod
redact-pii1.3.143.59 kBMIT
prod
1
3
2
traverse0.6.610.94 kBMIT
prod
uuid3.0.17.03 kBMIT
prod
1

Visualizations