Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 16, 2024 via pnpm

express-microservice-starter 0.5.21

An express-based Node.js API bootstrapping module for microservices.
Package summary
Share
29
issues
6
critical severity
vulnerability
3
license
3
12
high severity
vulnerability
5
license
2
meta
5
6
moderate severity
vulnerability
5
license
1
5
low severity
vulnerability
2
license
3
8
licenses
106
MIT
12
ISC
3
BSD-3-Clause
7
other licenses
N/A
3
BSD-2-Clause
1
BSD
1
Apache 2.0
1
+ 1 more
Package created
12 May 2015
Version published
17 Jun 2016
Maintainers
3
Total deps
128
Direct deps
17
License
ISC

Issues

29

6 critical severity issues

critical
Recommendation: None
via: zoologist@0.4.14
Recommendation: Upgrade to version 4.17.12 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 1.12.1 or later
via: zoologist@0.4.14
Recommendation: Check the package code and files for license information
via: express-cache-response-directive@0.2.0
Recommendation: Check the package code and files for license information
via: konfig@0.2.1
Recommendation: Check the package code and files for license information
via: zoologist@0.4.14
Collapse
Expand

12 high severity issues

high
Recommendation: Upgrade to version 2.6.9 or later
via: express-cache-response-directive@0.2.0
Recommendation: Upgrade to version 4.17.11 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 3.13.1 or later
via: konfig@0.2.1
Recommendation: Upgrade to version 4.17.19 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 4.17.21 or later
via: express-validator@2.21.0
Recommendation: Validate that the package complies with your license policy
via: konfig@0.2.1
Recommendation: Validate that the package complies with your license policy
via: express-enrouten@1.3.0
via: konfig@0.2.1
via: konfig@0.2.1
via: bunyan@1.8.15 & others
via: node-uuid@1.4.8 & others
via: zoologist@0.4.14
Collapse
Expand

6 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 3.13.0 or later
via: konfig@0.2.1
Recommendation: Upgrade to version 4.17.21 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 13.7.0 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 1.1.9 or later
via: ip@0.3.3
Recommendation: Validate that the package complies with your license policy
via: konfig@0.2.1
Collapse
Expand

5 low severity issues

low
Recommendation: Upgrade to version 4.17.5 or later
via: express-validator@2.21.0
Recommendation: Upgrade to version 2.6.9 or later
via: express-cache-response-directive@0.2.0
Recommendation: Read and validate the license terms
via: konfig@0.2.1
Recommendation: Read and validate the license terms
via: express-enrouten@1.3.0
via: konfig@0.2.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
106 Packages, Including:
accepts@1.3.8
argparse@1.0.10
array-flatten@1.1.1
async@0.2.10
async@0.9.2
async@1.5.2
balanced-match@1.0.2
bluebird@2.11.0
bluebird@3.4.7
body-parser@1.20.2
brace-expansion@1.1.11
bunyan@1.8.15
bytes@3.1.2
call-bind@1.0.7
caller@1.1.0
coffee-script@1.12.7
coffee-script@1.9.3
concat-map@0.0.1
content-disposition@0.5.4
content-type@1.0.5
cookie-signature@1.0.6
cookie@0.6.0
cors@2.8.5
cson@2.0.0
debug@2.6.9
debuglog@1.0.1
define-data-property@1.1.4
depd@2.0.0
destroy@1.2.0
ee-first@1.1.1
encodeurl@1.0.2
es-define-property@1.0.0
es-errors@1.3.0
escape-html@1.0.3
etag@1.8.1
express-cache-response-directive@0.2.0
express-partial-response@0.3.4
express-validator@2.21.0
express@4.19.2
finalhandler@1.2.0
forwarded@0.2.0
fresh@0.5.2
function-bind@1.1.2
get-intrinsic@1.2.4
gopd@1.0.1
has-property-descriptors@1.0.2
has-proto@1.0.3
has-symbols@1.0.3
hasown@2.0.2
http-errors@2.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
12 Packages, Including:
custom-error-generator@7.0.0
express-microservice-starter@0.5.21
glob@6.0.4
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
minimatch@3.1.2
once@1.4.0
rimraf@2.4.5
setprototypeof@1.2.0
wrappy@1.0.2
zoologist@0.4.14

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
cson-parser@1.3.5
qs@6.11.0
sprintf-js@1.0.3

N/A

N/A
3 Packages, Including:
debug@1.0.5
requirefresh@1.1.2
underscore@1.4.4

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
dtrace-provider@0.8.8

BSD

Invalid
Not OSI Approved
1 Packages, Including:
esprima@2.0.0

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
express-enrouten@1.3.0

GNU Lesser General Public License v3.0 only

Weakly Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
use-patent-claims
Cannot
sublicense
hold-liable
Must
include-original
state-changes
disclose-source
include-license
include-copyright
include-install-instructions
1 Packages, Including:
konfig@0.2.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

17
All Dependencies CSV
β“˜ This is a list of express-microservice-starter 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
async1.5.238.01 kBMIT
prod
bluebird2.11.099.26 kBMIT
prod
body-parser1.20.214.75 kBMIT
prod
bunyan1.8.1558.89 kBMIT
prod
1
caller1.1.02.01 kBMIT
prod
cors2.8.56.03 kBMIT
prod
express-cache-response-directive0.2.04.88 kBMIT
prod
1
1
1
express-enrouten1.3.010.12 kBApache 2.0
prod
1
1
express-partial-response0.3.42.48 kBMIT
prod
express-validator2.21.031.53 kBMIT
prod
1
3
3
1
express4.19.2209.73 kBMIT
prod
ip0.3.35.67 kBMIT
prod
1
konfig0.2.14.53 kBLGPL-3.0
prod
1
4
2
2
node-uuid1.4.813.8 kBMIT
prod
1
optional0.1.41.45 kBMIT
prod
vitalsigns0.4.314.22 kBMIT
prod
zoologist0.4.147.63 kBISC
prod
3
3

Visualizations