Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 5, 2024 via pnpm

express-microservice-starter 0.5.14

An express-based Node.js API bootstrapping module for microservices.
Package summary
Share
28
issues
6
critical severity
vulnerability
3
license
3
12
high severity
vulnerability
5
license
2
meta
5
6
moderate severity
vulnerability
5
license
1
4
low severity
vulnerability
1
license
3
8
licenses
107
MIT
12
ISC
3
BSD-3-Clause
7
other licenses
N/A
3
BSD-2-Clause
1
BSD
1
Apache 2.0
1
+ 1 more
Package created
12 May 2015
Version published
19 Nov 2015
Maintainers
3
Total deps
129
Direct deps
16
License
ISC

Issues

28

6 critical severity issues

critical
Recommendation: None
via: zoologist@0.4.14
Recommendation: Upgrade to version 4.17.12 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 1.12.1 or later
via: zoologist@0.4.14
Recommendation: Check the package code and files for license information
via: express-cache-response-directive@0.2.0
Recommendation: Check the package code and files for license information
via: konfig@0.2.1
Recommendation: Check the package code and files for license information
via: zoologist@0.4.14
Collapse
Expand

12 high severity issues

high
Recommendation: Upgrade to version 2.6.9 or later
via: express-cache-response-directive@0.2.0
Recommendation: Upgrade to version 4.17.21 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 4.17.11 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 3.13.1 or later
via: konfig@0.2.1
Recommendation: Upgrade to version 4.17.19 or later
via: express-validator@2.21.0
Recommendation: Validate that the package complies with your license policy
via: konfig@0.2.1
Recommendation: Validate that the package complies with your license policy
via: express-enrouten@1.3.0
via: konfig@0.2.1
via: konfig@0.2.1
via: bunyan@1.8.15 & others
via: zoologist@0.4.14
via: zoologist@0.4.14
Collapse
Expand

6 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 3.13.0 or later
via: konfig@0.2.1
Recommendation: Upgrade to version 2.6.9 or later
via: express-cache-response-directive@0.2.0
Recommendation: Upgrade to version 4.17.21 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 13.7.0 or later
via: express-validator@2.21.0
Recommendation: Validate that the package complies with your license policy
via: konfig@0.2.1
Collapse
Expand

4 low severity issues

low
Recommendation: Upgrade to version 4.17.5 or later
via: express-validator@2.21.0
Recommendation: Read and validate the license terms
via: konfig@0.2.1
Recommendation: Read and validate the license terms
via: express-enrouten@1.3.0
via: konfig@0.2.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
107 Packages, Including:
accepts@1.3.8
argparse@1.0.10
array-flatten@1.1.1
async@0.2.10
async@0.9.2
async@1.5.2
balanced-match@1.0.2
bluebird@2.11.0
bluebird@3.4.7
body-parser@1.20.1
body-parser@1.20.2
brace-expansion@1.1.11
bunyan@1.8.15
bytes@3.1.2
call-bind@1.0.5
caller@1.1.0
coffee-script@1.12.7
coffee-script@1.9.3
concat-map@0.0.1
content-disposition@0.5.4
content-type@1.0.5
cookie-signature@1.0.6
cookie@0.5.0
cors@2.8.5
cson@2.0.0
debug@2.6.9
debuglog@1.0.1
define-data-property@1.1.1
depd@2.0.0
destroy@1.2.0
ee-first@1.1.1
encodeurl@1.0.2
es-errors@1.3.0
escape-html@1.0.3
etag@1.8.1
express-cache-response-directive@0.2.0
express-partial-response@0.3.4
express-validator@2.21.0
express@4.18.2
finalhandler@1.2.0
forwarded@0.2.0
fresh@0.5.2
function-bind@1.1.2
get-intrinsic@1.2.3
gopd@1.0.1
has-property-descriptors@1.0.1
has-proto@1.0.1
has-symbols@1.0.3
hasown@2.0.0
http-errors@2.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
12 Packages, Including:
custom-error-generator@7.0.0
express-microservice-starter@0.5.14
glob@6.0.4
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
minimatch@3.1.2
once@1.4.0
rimraf@2.4.5
setprototypeof@1.2.0
wrappy@1.0.2
zoologist@0.4.14

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
cson-parser@1.3.5
qs@6.11.0
sprintf-js@1.0.3

N/A

N/A
3 Packages, Including:
debug@1.0.5
requirefresh@1.1.2
underscore@1.4.4

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
dtrace-provider@0.8.8

BSD

Invalid
Not OSI Approved
1 Packages, Including:
esprima@2.0.0

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
express-enrouten@1.3.0

GNU Lesser General Public License v3.0 only

Weakly Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
use-patent-claims
Cannot
sublicense
hold-liable
Must
include-original
state-changes
disclose-source
include-license
include-copyright
include-install-instructions
1 Packages, Including:
konfig@0.2.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

16
All Dependencies CSV
β“˜ This is a list of express-microservice-starter 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
async1.5.238.01 kBMIT
prod
bluebird2.11.099.26 kBMIT
prod
body-parser1.20.214.75 kBMIT
prod
bunyan1.8.1558.89 kBMIT
prod
1
caller1.1.02.01 kBMIT
prod
cors2.8.56.03 kBMIT
prod
express-cache-response-directive0.2.04.88 kBMIT
prod
1
1
1
express-enrouten1.3.010.12 kBApache 2.0
prod
1
1
express-partial-response0.3.42.48 kBMIT
prod
express-validator2.21.031.53 kBMIT
prod
1
3
3
1
express4.18.254.5 kBMIT
prod
ip0.3.35.67 kBMIT
prod
konfig0.2.14.53 kBLGPL-3.0
prod
1
4
2
2
optional0.1.41.45 kBMIT
prod
vitalsigns0.4.314.22 kBMIT
prod
zoologist0.4.147.63 kBISC
prod
3
3

Visualizations