Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 19, 2024 via pnpm
Package summary
Share
50
issues
1
critical severity
license
1
30
high severity
vulnerability
5
license
3
meta
22
14
moderate severity
vulnerability
8
license
1
meta
5
5
low severity
license
5
15
licenses
1324
MIT
82
ISC
37
BSD-2-Clause
76
other licenses
BSD-3-Clause
30
Apache-2.0
26
(MIT OR CC0-1.0)
5
0BSD
4
+ 8 more
Package created
4 May 2021
Version published
16 Dec 2021
Maintainers
1
Total deps
1519
Direct deps
23
License
MIT

Issues

50

1 critical severity issue

critical
Recommendation: Check the package code and files for license information
via: gatsby-plugin-image@2.25.0 & others
Collapse
Expand

30 high severity issues

high
Recommendation: Upgrade to version 0.32.6 or later
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Upgrade to version 3.0.5 or later
via: gatsby-plugin-plausible@0.0.7
Recommendation: Upgrade to version 5.3.4 or later
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: None
via: gatsby-plugin-offline@5.25.0
Recommendation: Upgrade to version 2.7.1 or later
via: gatsby-transformer-remark@5.25.1
Recommendation: Read and validate the license terms
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Validate that the license expression complies with your license policy
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Read and validate the license terms
via: gatsby-plugin-robots-txt@1.8.0
via: gatsby-plugin-offline@5.25.0
via: gatsby-plugin-offline@5.25.0
via: gatsby-plugin-offline@5.25.0
via: gatsby-plugin-offline@5.25.0
via: gatsby-plugin-offline@5.25.0
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-offline@5.25.0
via: gatsby-plugin-offline@5.25.0
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Collapse
Expand

14 moderate severity issues

moderate
Recommendation: Upgrade to version 11.8.5 or later
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Upgrade to version 2.3.2 or later
via: gatsby-transformer-remark@5.25.1
Recommendation: Upgrade to version 2.3.1 or later
via: gatsby-transformer-remark@5.25.1
Recommendation: Upgrade to version 8.4.31 or later
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Upgrade to version 6.4.2 or later
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Upgrade to version 7.5.2 or later
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Upgrade to version 0.28.0 or later
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Upgrade to version 2.12.1 or later
via: gatsby-transformer-remark@5.25.1
Recommendation: Validate that the package complies with your license policy
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-image@2.25.0
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Collapse
Expand

5 low severity issues

low
Recommendation: Read and validate the license terms
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Read and validate the license terms
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Read and validate the license terms
via: gatsby-plugin-robots-txt@1.8.0
Recommendation: Read and validate the license terms
via: gatsby-plugin-gdpr-cookies@2.0.9 & others
Recommendation: Read and validate the license terms
via: gatsby-plugin-robots-txt@1.8.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
1324 Packages, Including:
@ardatan/relay-compiler@12.0.0
@babel/code-frame@7.12.11
@babel/code-frame@7.24.2
@babel/compat-data@7.24.4
@babel/core@7.24.5
@babel/eslint-parser@7.24.5
@babel/generator@7.24.5
@babel/helper-annotate-as-pure@7.22.5
@babel/helper-builder-binary-assignment-operator-visitor@7.22.15
@babel/helper-compilation-targets@7.23.6
@babel/helper-create-class-features-plugin@7.24.5
@babel/helper-create-regexp-features-plugin@7.22.15
@babel/helper-define-polyfill-provider@0.6.2
@babel/helper-environment-visitor@7.22.20
@babel/helper-function-name@7.23.0
@babel/helper-hoist-variables@7.22.5
@babel/helper-member-expression-to-functions@7.24.5
@babel/helper-module-imports@7.24.3
@babel/helper-module-transforms@7.24.5
@babel/helper-optimise-call-expression@7.22.5
@babel/helper-plugin-utils@7.24.5
@babel/helper-remap-async-to-generator@7.22.20
@babel/helper-replace-supers@7.24.1
@babel/helper-simple-access@7.24.5
@babel/helper-skip-transparent-expression-wrappers@7.22.5
@babel/helper-split-export-declaration@7.24.5
@babel/helper-string-parser@7.24.1
@babel/helper-validator-identifier@7.24.5
@babel/helper-validator-option@7.23.5
@babel/helper-wrap-function@7.24.5
@babel/helpers@7.24.5
@babel/highlight@7.24.5
@babel/parser@7.24.5
@babel/plugin-bugfix-firefox-class-in-computed-class-key@7.24.5
@babel/plugin-bugfix-safari-id-destructuring-collision-in-function-expression@7.24.1
@babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining@7.24.1
@babel/plugin-bugfix-v8-static-class-fields-redefine-readonly@7.24.1
@babel/plugin-proposal-class-properties@7.18.6
@babel/plugin-proposal-nullish-coalescing-operator@7.18.6
@babel/plugin-proposal-numeric-separator@7.18.6
@babel/plugin-proposal-object-rest-spread@7.20.7
@babel/plugin-proposal-optional-chaining@7.21.0
@babel/plugin-proposal-private-property-in-object@7.21.0-placeholder-for-preset-env.2
@babel/plugin-syntax-async-generators@7.8.4
@babel/plugin-syntax-class-properties@7.12.13
@babel/plugin-syntax-class-static-block@7.14.5
@babel/plugin-syntax-dynamic-import@7.8.3
@babel/plugin-syntax-export-namespace-from@7.8.3
@babel/plugin-syntax-flow@7.24.1
@babel/plugin-syntax-import-assertions@7.24.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
82 Packages, Including:
@trysound/sax@0.2.0
ansi-align@3.0.1
anymatch@3.1.3
async-cache@1.1.0
at-least-node@1.0.0
boolbase@1.0.0
chownr@1.1.4
cli-width@3.0.0
cliui@6.0.0
css-declaration-sorter@6.4.1
d@1.0.2
electron-to-chromium@1.4.774
es5-ext@0.10.64
es6-symbol@3.1.4
es6-weak-map@2.0.3
esniff@2.0.1
ext@1.7.0
fastq@1.17.1
flatted@3.3.1
fs-exists-cached@1.0.0
fs.realpath@1.0.0
get-caller-file@2.0.5
get-own-enumerable-property-symbols@3.0.2
github-slugger@1.5.0
glob-parent@5.1.2
glob@7.2.3
graceful-fs@4.2.11
hosted-git-info@2.8.9
hosted-git-info@3.0.8
icss-utils@5.1.0
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
ini@2.0.0
isexe@2.0.0
lru-cache@4.0.0
lru-cache@4.1.5
lru-cache@5.1.1
lru-cache@6.0.0
memoizee@0.4.15
minimatch@3.0.4
minimatch@3.1.2
mute-stream@0.0.8
next-tick@1.1.0
objectFitPolyfill@2.3.5
once@1.4.0
physical-cpu-count@2.0.0
picocolors@0.2.1
picocolors@1.0.1
postcss-modules-extract-imports@3.1.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
37 Packages, Including:
@typescript-eslint/parser@4.33.0
@typescript-eslint/typescript-estree@4.33.0
cheerio-select@2.1.0
configstore@5.0.1
css-select@4.3.0
css-select@5.1.0
css-what@6.1.0
damerau-levenshtein@1.0.8
domelementtype@2.3.0
domhandler@3.3.0
domhandler@4.3.1
domhandler@5.0.3
domutils@2.8.0
domutils@3.1.0
dotenv-expand@5.1.0
dotenv@7.0.0
dotenv@8.6.0
entities@2.2.0
entities@4.5.0
eslint-scope@5.1.1
espree@7.3.1
esprima@4.0.1
esrecurse@4.3.0
estraverse@4.3.0
estraverse@5.3.0
esutils@2.0.3
glob-to-regexp@0.4.1
http-cache-semantics@4.1.1
normalize-package-data@2.5.0
nth-check@2.1.1
regjsparser@0.9.1
stringify-object@3.3.0
terser@5.31.0
update-notifier@5.1.0
uri-js@4.4.1
webidl-conversions@3.0.1
yurnalist@2.1.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
30 Packages, Including:
@hapi/address@2.1.4
@hapi/bourne@1.3.2
@hapi/hoek@8.5.1
@hapi/hoek@9.3.0
@hapi/joi@15.1.1
@hapi/topo@3.1.6
@hapi/topo@5.1.0
@humanwhocodes/object-schema@1.2.1
@sideway/address@4.1.5
@sideway/formula@3.0.1
@sideway/pinpoint@2.0.0
@xtuc/ieee754@1.2.0
duplexer3@0.1.5
eslint-plugin-flowtype@5.10.0
esquery@1.5.0
filesize@8.0.7
flat@5.0.2
ieee754@1.2.1
immutable@3.7.6
joi@17.13.1
qs@6.11.0
serialize-javascript@5.0.1
serialize-javascript@6.0.2
signedsource@1.0.0
source-map-js@1.2.0
source-map@0.6.1
source-map@0.7.4
sprintf-js@1.0.3
sprintf-js@1.1.3
table@6.8.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
26 Packages, Including:
@ampproject/remapping@2.3.0
@humanwhocodes/config-array@0.5.0
@swc/helpers@0.4.36
@webassemblyjs/leb128@1.11.6
@xtuc/long@4.2.2
ansi-html-community@0.0.8
aria-query@5.3.0
axobject-query@3.2.1
bser@2.1.1
detect-libc@1.0.3
detect-libc@2.0.3
doctrine@2.1.0
doctrine@3.0.0
eslint-visitor-keys@1.3.0
eslint-visitor-keys@2.1.0
fb-watchman@2.0.2
human-signals@2.1.0
idb-keyval@3.2.0
opentracing@0.14.7
rxjs@6.6.7
sharp@0.30.7
spdx-correct@3.2.0
true-case-path@2.2.1
tunnel-agent@0.6.0
typescript@5.4.5
validate-npm-package-license@3.0.4

(MIT OR CC0-1.0)

Public Domain
5 Packages, Including:
type-fest@0.13.1
type-fest@0.20.2
type-fest@0.21.3
type-fest@0.6.0
type-fest@0.8.1

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
4 Packages, Including:
password-prompt@1.1.3
tslib@1.14.1
tslib@2.4.1
tslib@2.6.2

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
3 Packages, Including:
language-subtag-registry@0.3.22
mdn-data@2.0.14
spdx-license-ids@3.0.17

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
2 Packages, Including:
fs-monkey@1.0.6
memfs@3.5.3

Mozilla Public License 2.0

Weakly Protective
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
place-warranty
use-patent-claims
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
disclose-source
include-original
1 Packages, Including:
axe-core@4.7.0

Creative Commons Attribution 4.0 International

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
caniuse-lite@1.0.30001620

(MIT OR WTFPL)

Permissive
1 Packages, Including:
expand-template@2.0.3

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

N/A

N/A
1 Packages, Including:
valid-url@1.0.9
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

23
All Dependencies CSV
β“˜ This is a list of gatsby-theme-portfolio-minimal 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@fontsource/roboto4.5.83.7 MBMIT
prod
gatsby-plugin-gdpr-cookies2.0.914.86 kBMIT
prod
19
10
3
gatsby-plugin-image2.25.0149.34 kBMIT
prod
1
19
11
3
gatsby-plugin-manifest4.25.024.24 kBMIT
prod
19
10
3
gatsby-plugin-offline5.25.018.86 kBMIT
prod
27
10
3
gatsby-plugin-plausible0.0.75 kBMIT
prod
20
10
3
gatsby-plugin-react-helmet5.25.06.31 kBMIT
prod
19
10
3
gatsby-plugin-robots-txt1.8.05.58 kBMIT
prod
20
10
5
gatsby-plugin-sharp4.25.1857.36 kBMIT
prod peer
19
10
3
gatsby-plugin-sitemap5.25.015.24 kBMIT
prod
19
10
3
gatsby-source-filesystem4.25.021.68 kBMIT
prod peer
1
19
10
3
gatsby-transformer-json4.25.07.48 kBMIT
prod
19
10
3
gatsby-transformer-remark5.25.121.21 kBMIT
prod
20
13
3
gatsby-transformer-sharp4.25.024.67 kBMIT
prod
19
10
3
gatsby4.25.95.37 MBMIT
prod peer
19
10
3
normalize.css8.0.15.64 kBMIT
prod
react-cookie-consent6.4.1104.89 kBMIT
prod
react-dom17.0.2727.53 kBMIT
prod peer
react-helmet6.1.024.48 kBMIT
prod peer
react17.0.272.94 kBMIT
prod peer
reading-time1.5.04.16 kBMIT
prod
slugify1.6.68.5 kBMIT
prod
tiny-skeleton-loader-react1.2.14.02 kBMIT
prod

Visualizations