Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 28, 2024 via pnpm
Package summary
Share
10
issues
1
critical severity
vulnerability
1
7
high severity
license
2
meta
5
2
low severity
license
2
9
licenses
127
MIT
18
Apache-2.0
16
ISC
29
other licenses
BSD-3-Clause
15
BSD-2-Clause
9
SEE LICENSE IN LICENSE
2
Python-2.0
1
+ 2 more
Package created
6 May 2016
Version published
21 Oct 2021
Maintainers
6
Total deps
190
Direct deps
8
License
SEE LICENSE IN LICENSE

Issues

10

1 critical severity issue

critical
Recommendation: Upgrade to version 7.2.5 or later
via: redact-pii@3.4.0
Collapse
Expand

7 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: dashbot-logger@1.1.4
Recommendation: Validate that the package complies with your license policy
via: dashbot@12.1.0
via: dashbot-logger@1.1.4
via: redact-pii@3.4.0
via: dashbot-logger@1.1.4
via: uuid@3.0.1
via: dashbot-logger@1.1.4
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: dashbot-logger@1.1.4
Recommendation: Read and validate the license terms
via: dashbot@12.1.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
127 Packages, Including:
@babel/helper-string-parser@7.24.1
@babel/helper-validator-identifier@7.22.20
@babel/parser@7.24.4
@babel/types@7.24.0
@types/glob@8.1.0
@types/linkify-it@3.0.5
@types/long@4.0.2
@types/markdown-it@12.2.3
@types/mdurl@1.0.5
@types/minimatch@5.1.2
@types/node@20.12.7
@types/rimraf@3.0.2
abort-controller@3.0.0
acorn-jsx@5.3.2
acorn@8.11.3
agent-base@6.0.2
ansi-regex@5.0.1
ansi-styles@4.3.0
arrify@2.0.1
available-typed-arrays@1.0.7
balanced-match@1.0.2
base64-js@1.5.1
bignumber.js@9.1.2
bluebird@3.7.2
brace-expansion@2.0.1
buffer@4.9.2
call-bind@1.0.7
catharsis@0.9.0
chalk@4.1.2
color-convert@2.0.1
color-name@1.1.4
debug@4.3.4
deep-is@0.1.4
define-data-property@1.1.4
duplexify@4.1.3
emoji-regex@8.0.0
end-of-stream@1.4.4
es-define-property@1.0.0
es-errors@1.3.0
es6-promise@4.1.0
escalade@3.1.2
escape-string-regexp@2.0.0
event-target-shim@5.0.1
events@1.1.1
extend@3.0.2
fast-levenshtein@2.0.6
for-each@0.3.3
function-bind@1.1.2
generic-pool@3.9.0
get-intrinsic@1.2.4

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
18 Packages, Including:
@google-cloud/dlp@4.4.3
@grpc/grpc-js@1.8.21
@grpc/proto-loader@0.7.12
@jsdoc/salty@0.2.8
aws-sdk@2.1608.0
ecdsa-sig-formatter@1.0.11
eslint-visitor-keys@3.4.3
fast-text-encoding@1.0.6
gaxios@5.1.3
gcp-metadata@5.3.0
google-auth-library@8.9.0
google-gax@3.6.1
jmespath@0.16.0
js2xmlparser@4.0.2
jsdoc@4.0.2
long@5.2.3
proto3-json-serializer@1.1.1
xmlcreate@2.0.4

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
16 Packages, Including:
cliui@8.0.1
fs.realpath@1.0.0
get-caller-file@2.0.5
glob@8.1.0
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
lru-cache@6.0.0
minimatch@5.1.6
once@1.4.0
sax@1.2.1
semver@7.6.0
wrappy@1.0.2
y18n@5.0.8
yallist@4.0.0
yargs-parser@21.1.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
15 Packages, Including:
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
buffer-equal-constant-time@1.0.1
ieee754@1.1.13
protobufjs-cli@1.1.1
protobufjs@7.2.4
source-map@0.6.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
entities@2.1.0
escodegen@1.14.3
espree@9.6.1
esprima@4.0.1
estraverse@4.3.0
estraverse@5.3.0
esutils@2.0.3
uglify-js@3.17.4
webidl-conversions@3.0.1

SEE LICENSE IN LICENSE

Invalid
Not OSI Approved
2 Packages, Including:
dashbot-logger@1.1.4
dashbot@12.1.0

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
markdown-it-anchor@8.6.7

(BSD-3-Clause OR GPL-2.0)

Permissive
1 Packages, Including:
node-forge@1.3.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

8
All Dependencies CSV
β“˜ This is a list of dashbot 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
dashbot-logger1.1.43.84 kBSEE LICENSE IN LICENSE
prod peer
4
1
es6-promise4.1.073.15 kBMIT
prod
isomorphic-fetch3.0.03.2 kBMIT
prod
lodash4.17.21311.49 kBMIT
prod
meld1.3.29.07 kBMIT
prod
redact-pii3.4.0103.46 kBMIT
prod peer
1
1
traverse0.6.610.94 kBMIT
prod
uuid3.0.17.03 kBMIT
prod
1

Visualizations