Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 27, 2024 via pnpm

firebase-tools 12.5.4

Command-Line Interface for Firebase
Package summary
Share
18
issues
3
critical severity
vulnerability
1
license
2
9
high severity
license
4
meta
5
3
moderate severity
vulnerability
2
meta
1
3
low severity
license
3
15
licenses
450
MIT
71
ISC
35
Apache-2.0
56
other licenses
BSD-3-Clause
28
BSD-2-Clause
14
N/A
2
BlueOak-1.0.0
2
+ 8 more
Package created
15 Jan 2014
Version published
12 Sep 2023
Maintainers
4
Total deps
612
Direct deps
60
License
MIT

Issues

18

3 critical severity issues

critical
Recommendation: Upgrade to version 7.2.5 or later
via: @google-cloud/pubsub@3.7.5
Recommendation: Check the package code and files for license information
via: cli-table@0.3.11
Recommendation: Check the package code and files for license information
via: superstatic@9.0.3
Collapse
Expand

9 high severity issues

high
Recommendation: Read and validate the license terms
via: exegesis@4.1.2 & others
Recommendation: Read and validate the license terms
via: exegesis@4.1.2 & others
Recommendation: Validate that the package complies with your license policy
via: exegesis@4.1.2 & others
Recommendation: Validate that the license expression complies with your license policy
via: superstatic@9.0.3 & others
via: request@2.88.2
via: @google-cloud/pubsub@3.7.5
via: superstatic@9.0.3
via: request@2.88.2
via: request@2.88.2
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Upgrade to version 4.1.3 or later
via: request@2.88.2
Recommendation: None
via: request@2.88.2
via: superstatic@9.0.3
Collapse
Expand

3 low severity issues

low
Recommendation: Read and validate the license terms
via: exegesis@4.1.2 & others
Recommendation: Read and validate the license terms
via: exegesis@4.1.2 & others
Recommendation: Read and validate the license terms
via: exegesis@4.1.2 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
450 Packages, Including:
@apidevtools/json-schema-ref-parser@9.1.2
@babel/helper-string-parser@7.24.1
@babel/helper-validator-identifier@7.22.20
@babel/parser@7.24.4
@babel/types@7.24.0
@colors/colors@1.5.0
@colors/colors@1.6.0
@dabh/diagnostics@2.0.3
@jsdevtools/ono@7.1.3
@pkgjs/parseargs@0.11.0
@pnpm/config.env-replace@1.1.0
@pnpm/network.ca-file@1.0.2
@pnpm/npm-conf@2.2.2
@tootallnate/quickjs-emscripten@0.23.0
@types/duplexify@3.6.4
@types/glob@8.1.0
@types/json-schema@7.0.15
@types/linkify-it@3.0.5
@types/long@4.0.2
@types/markdown-it@12.2.3
@types/mdurl@1.0.5
@types/minimatch@5.1.2
@types/node@20.12.7
@types/rimraf@3.0.2
@types/triple-beam@1.3.5
abort-controller@3.0.0
accepts@1.3.8
acorn-jsx@5.3.2
acorn@8.11.3
agent-base@6.0.2
agent-base@7.1.1
aggregate-error@3.1.0
ajv-formats@2.1.1
ajv@6.12.6
ajv@8.12.0
ansi-escapes@4.3.2
ansi-escapes@6.2.1
ansi-regex@5.0.1
ansi-regex@6.0.1
ansi-styles@4.3.0
ansi-styles@6.2.1
ansicolors@0.3.2
archiver-utils@2.1.0
archiver-utils@3.0.4
archiver@5.3.2
argparse@1.0.10
array-flatten@1.1.1
array-flatten@3.0.0
arrify@2.0.1
as-array@2.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
71 Packages, Including:
@isaacs/cliui@8.0.2
@npmcli/agent@2.2.2
@npmcli/fs@3.1.0
abbrev@2.0.0
ansi-align@3.0.1
anymatch@3.1.3
cacache@18.0.2
chownr@2.0.0
cli-width@3.0.0
cliui@8.0.1
foreground-child@3.1.1
fs-minipass@2.1.0
fs-minipass@3.0.3
fs.realpath@1.0.0
get-caller-file@2.0.5
glob-parent@5.1.2
glob@10.3.12
glob@7.2.3
glob@8.1.0
graceful-fs@4.2.10
graceful-fs@4.2.11
har-schema@2.0.0
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
ini@2.0.0
isexe@2.0.0
isexe@3.1.1
json-stringify-safe@5.0.1
libsodium-wrappers@0.7.13
libsodium@0.7.13
lru-cache@10.2.1
lru-cache@6.0.0
lru-cache@7.18.3
make-fetch-happen@13.0.0
minimatch@3.1.2
minimatch@5.1.6
minimatch@6.2.0
minimatch@9.0.4
minipass-collect@2.0.1
minipass-flush@1.0.5
minipass-pipeline@1.2.4
minipass-sized@1.0.3
minipass@3.3.6
minipass@5.0.0
minipass@7.0.4
mute-stream@0.0.8
nopt@7.2.0
once@1.4.0
proc-log@3.0.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
35 Packages, Including:
@google-cloud/paginator@4.0.1
@google-cloud/precise-date@3.0.1
@google-cloud/projectify@3.0.0
@google-cloud/promisify@2.0.4
@google-cloud/pubsub@3.7.5
@grpc/grpc-js@1.8.21
@grpc/proto-loader@0.7.12
@jsdoc/salty@0.2.8
@opentelemetry/api@1.8.0
@opentelemetry/semantic-conventions@1.3.1
aws-sign2@0.7.0
caseless@0.12.0
crc-32@1.2.2
ecdsa-sig-formatter@1.0.11
eslint-visitor-keys@3.4.3
exponential-backoff@3.1.1
fast-text-encoding@1.0.6
forever-agent@0.6.1
gaxios@4.3.3
gaxios@5.1.3
gcp-metadata@4.3.1
gcp-metadata@5.3.0
google-auth-library@7.14.1
google-auth-library@8.9.0
google-gax@3.6.1
js2xmlparser@4.0.2
jsdoc@4.0.2
long@5.2.3
oauth-sign@0.9.0
proto3-json-serializer@1.1.1
readdir-glob@1.1.3
request@2.88.2
rxjs@7.8.1
tunnel-agent@0.6.0
xmlcreate@2.0.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
28 Packages, Including:
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
bcrypt-pbkdf@1.0.2
buffer-equal-constant-time@1.0.1
filesize@6.4.0
heap-js@2.5.0
ieee754@1.2.1
install-artifact-from-github@1.3.5
protobufjs-cli@1.1.1
protobufjs@7.2.4
qs@6.11.0
qs@6.12.1
qs@6.5.3
re2@1.20.10
source-map@0.6.1
sprintf-js@1.0.3
sprintf-js@1.1.3
stream-chain@2.2.5
stream-json@1.8.0
tough-cookie@2.5.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
14 Packages, Including:
configstore@5.0.1
entities@2.1.0
escodegen@1.14.3
escodegen@2.1.0
espree@9.6.1
esprima@4.0.1
estraverse@4.3.0
estraverse@5.3.0
esutils@2.0.3
http-cache-semantics@4.1.1
uglify-js@3.17.4
update-notifier-cjs@5.1.6
uri-js@4.4.1
webidl-conversions@3.0.1

N/A

N/A
2 Packages, Including:
cli-table@0.3.11
valid-url@1.0.9

Blue Oak Model License 1.0.0

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
jackspeak@2.3.6
path-scurry@1.10.2

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
2 Packages, Including:
markdown-it-anchor@8.6.7
tweetnacl@0.14.5

(MIT OR CC0-1.0)

Public Domain
2 Packages, Including:
type-fest@0.20.2
type-fest@0.21.3

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

public domain

Invalid
Not OSI Approved
1 Packages, Including:
deep-freeze@0.0.1

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

(BSD-3-Clause OR GPL-2.0)

Permissive
1 Packages, Including:
node-forge@1.3.1

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
1 Packages, Including:
tslib@2.6.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

60
All Dependencies CSV
β“˜ This is a list of firebase-tools 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@google-cloud/pubsub3.7.5361.2 kBApache-2.0
prod
1
1
abort-controller3.0.017.14 kBMIT
prod
ajv6.12.6197.63 kBMIT
prod
archiver5.3.213.02 kBMIT
prod
async-lock1.3.26.06 kBMIT
prod
body-parser1.20.214.75 kBMIT
prod
chokidar3.6.025.83 kBMIT
prod
cjson0.3.35.92 kBMIT
prod
cli-table0.3.115.94 kBUNKNOWN
prod
1
colorette2.0.204.94 kBMIT
prod
commander4.1.126.55 kBMIT
prod
configstore5.0.13.32 kBBSD-2-Clause
prod
cors2.8.56.03 kBMIT
prod
cross-env5.2.18.94 kBMIT
prod
cross-spawn7.0.37.3 kBMIT
prod
csv-parse5.5.51.34 MBMIT
prod
exegesis-express4.0.04.6 kBMIT
prod
3
3
exegesis4.1.2320.59 kBMIT
prod
3
3
express4.19.2209.73 kBMIT
prod
filesize6.4.011.14 kBBSD-3-Clause
prod
form-data4.0.010.24 kBMIT
prod
fs-extra10.1.016.52 kBMIT
prod
glob7.2.315.08 kBISC
prod
google-auth-library7.14.191.53 kBApache-2.0
prod
inquirer8.2.623.24 kBMIT
prod
js-yaml3.14.175.07 kBMIT
prod
jsonwebtoken9.0.211.94 kBMIT
prod
leven3.1.02.44 kBMIT
prod
libsodium-wrappers0.7.1317 kBISC
prod
lodash4.17.21311.49 kBMIT
prod
marked-terminal5.2.012.67 kBMIT
prod
marked4.3.0103.63 kBMIT
prod peer
mime2.6.018.29 kBMIT
prod
minimatch3.1.211.66 kBISC
prod
morgan1.10.09.37 kBMIT
prod
node-fetch2.7.043.6 kBMIT
prod
open6.4.010.59 kBMIT
prod
ora5.4.16.74 kBMIT
prod
p-limit3.1.03.19 kBMIT
prod
portfinder1.0.326.38 kBMIT
prod
progress2.0.35.86 kBMIT
prod
proxy-agent6.4.023.17 kBMIT
prod
request2.88.257.83 kBApache-2.0
prod
3
2
retry0.13.16.39 kBMIT
prod
rimraf3.0.26.33 kBISC
prod
semver7.6.026.57 kBISC
prod optional
stream-chain2.2.59.66 kBBSD-3-Clause
prod
stream-json1.8.015.92 kBBSD-3-Clause
prod
strip-ansi6.0.11.99 kBMIT
prod
superstatic9.0.321.35 kBMIT
prod
1
4
1
2
tar6.2.1162.71 kBISC
prod optional
tcp-port-used1.0.26.15 kBMIT
prod
tmp0.2.353.08 kBMIT
prod
triple-beam1.4.11 BMIT
prod
universal-analytics0.5.325.88 kBMIT
prod
update-notifier-cjs5.1.66.65 kBBSD-2-Clause
prod
1
uuid8.3.227.32 kBMIT
prod
winston-transport4.7.011.56 kBMIT
prod
winston3.13.0267.69 kBMIT
prod
ws7.5.928.37 kBMIT
prod

Visualizations