Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 8, 2024 via pnpm

express-microservice-starter 0.7.2

An express-based Node.js API bootstrapping module for microservices.
Package summary
Share
26
issues
4
critical severity
vulnerability
2
license
2
16
high severity
vulnerability
4
license
2
meta
10
3
moderate severity
vulnerability
2
license
1
3
low severity
license
3
9
licenses
266
MIT
17
ISC
5
BSD-3-Clause
10
other licenses
BSD-2-Clause
4
N/A
2
BSD
1
Apache 2.0
1
+ 2 more
Package created
12 May 2015
Version published
7 Mar 2019
Maintainers
3
Total deps
298
Direct deps
20
License
ISC

Issues

26

4 critical severity issues

critical
Recommendation: None
via: zoologist@0.5.9
Recommendation: Upgrade to version 1.12.1 or later
via: zoologist@0.5.9
Recommendation: Check the package code and files for license information
via: konfig@0.2.1
Recommendation: Check the package code and files for license information
via: zoologist@0.5.9
Collapse
Expand

16 high severity issues

high
Recommendation: None
via: request-ip@2.2.0
Recommendation: None
via: swagger-tools@0.10.4
Recommendation: Upgrade to version 3.13.1 or later
via: konfig@0.2.1
Recommendation: Upgrade to version 6.5.3 or later
via: swagger-tools@0.10.4
Recommendation: Validate that the package complies with your license policy
via: konfig@0.2.1
Recommendation: Validate that the package complies with your license policy
via: express-enrouten@1.3.0
via: konfig@0.2.1
via: konfig@0.2.1
via: swagger-tools@0.10.4
via: swagger-tools@0.10.4
via: bunyan@1.8.15 & others
via: swagger-tools@0.10.4
via: swagger-tools@0.10.4
via: swagger-tools@0.10.4
via: swagger-tools@0.10.4
via: uuid@3.4.0 & others
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Upgrade to version 3.13.0 or later
via: konfig@0.2.1
Recommendation: Upgrade to version 13.7.0 or later
via: express-validator@4.3.0 & others
Recommendation: Validate that the package complies with your license policy
via: konfig@0.2.1
Collapse
Expand

3 low severity issues

low
Recommendation: Read and validate the license terms
via: konfig@0.2.1
Recommendation: Read and validate the license terms
via: express-enrouten@1.3.0
via: konfig@0.2.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
266 Packages, Including:
@types/body-parser@1.19.5
@types/connect@3.4.38
@types/express-serve-static-core@4.19.0
@types/express@4.0.39
@types/http-errors@2.0.4
@types/mime@1.3.5
@types/node@20.12.10
@types/qs@6.9.15
@types/range-parser@1.2.7
@types/send@0.17.4
@types/serve-static@1.15.7
accepts@1.3.8
address@1.2.2
append-field@1.0.0
argparse@1.0.10
array-buffer-byte-length@1.0.1
array-flatten@1.1.1
arraybuffer.prototype.slice@1.0.3
asap@2.0.6
async@0.2.10
async@0.9.2
async@2.6.4
asynckit@0.4.0
available-typed-arrays@1.0.7
balanced-match@1.0.2
bluebird@2.11.0
bluebird@3.7.2
body-parser@1.18.2
body-parser@1.20.2
brace-expansion@1.1.11
buffer-from@1.1.2
bunyan@1.8.15
busboy@0.2.14
bytes@3.0.0
bytes@3.1.2
call-bind@1.0.7
caller@1.0.1
coffee-script@1.12.7
coffee-script@1.9.3
combined-stream@1.0.8
commander@2.11.0
commander@4.1.1
component-emitter@1.3.1
concat-map@0.0.1
concat-stream@1.6.2
content-disposition@0.5.4
content-type@1.0.5
cookie-signature@1.0.6
cookie@0.6.0
cookiejar@2.1.4

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
17 Packages, Including:
custom-error-generator@7.0.0
dezalgo@1.0.4
express-microservice-starter@0.7.2
glob@6.0.4
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.3
inherits@2.0.4
minimatch@3.1.2
once@1.4.0
rimraf@2.4.5
semver@7.6.1
setprototypeof@1.0.3
setprototypeof@1.1.0
setprototypeof@1.2.0
wrappy@1.0.2
zoologist@0.5.9

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
cson-parser@1.3.5
qs@6.11.0
qs@6.12.1
qs@6.5.1
sprintf-js@1.0.3

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
4 Packages, Including:
dtrace-provider@0.8.8
esprima@4.0.1
memory-cache@0.1.6
uri-js@4.4.1

N/A

N/A
2 Packages, Including:
requirefresh@1.1.2
underscore@1.4.4

BSD

Invalid
Not OSI Approved
1 Packages, Including:
esprima@2.0.0

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
express-enrouten@1.3.0

GNU Lesser General Public License v3.0 only

Weakly Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
use-patent-claims
Cannot
sublicense
hold-liable
Must
include-original
state-changes
disclose-source
include-license
include-copyright
include-install-instructions
1 Packages, Including:
konfig@0.2.1

(WTFPL OR MIT)

Permissive
1 Packages, Including:
spark-md5@3.0.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

20
All Dependencies CSV
β“˜ This is a list of express-microservice-starter 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
address1.2.24.38 kBMIT
prod
async2.6.4120.04 kBMIT
prod
bluebird3.7.2136.03 kBMIT
prod
body-parser1.20.214.75 kBMIT
prod
bunyan1.8.1558.89 kBMIT
prod
1
caller1.0.12.33 kBMIT
prod
cors2.8.56.03 kBMIT
prod
express-cache-response-directive1.1.04.92 kBMIT
prod
express-enrouten1.3.010.12 kBApache 2.0
prod
1
1
express-partial-response0.3.42.48 kBMIT
prod
express-validator4.3.020.81 kBMIT
prod
1
express4.19.2209.73 kBMIT
prod
ip1.1.915.09 kBMIT
prod
konfig0.2.14.53 kBLGPL-3.0
prod
1
4
2
2
optional0.1.41.45 kBMIT
prod
request-ip2.2.03.78 kBMIT
prod
1
swagger-tools0.10.4585.82 kBMIT
prod
8
1
uuid3.4.011.87 kBMIT
prod
1
vitalsigns0.4.314.22 kBMIT
prod
zoologist0.5.921.52 kBISC
prod
3
2

Visualizations