Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 6, 2024 via pnpm

godsend 0.5.9

Separation of concerns for streaming microservices.
Package summary
Share
41
issues
18
critical severity
vulnerability
4
license
14
12
high severity
vulnerability
8
meta
4
10
moderate severity
vulnerability
5
meta
5
1
low severity
vulnerability
1
4
licenses
170
MIT
14
N/A
11
ISC
1
BSD-3-Clause
Package created
12 Mar 2017
Version published
8 Jun 2017
Maintainers
1
Total deps
196
Direct deps
12
License
MIT

Issues

41

18 critical severity issues

critical
Recommendation: Upgrade to version 1.6.2 or later
via: socket.io-client@1.7.3 & others
Recommendation: Upgrade to version 1.6.1 or later
via: socket.io-client@1.7.3 & others
Recommendation: Upgrade to version 3.3.3 or later
via: socket.io-client@1.7.3 & others
Recommendation: Upgrade to version 1.2.6 or later
via: minimist@1.2.0 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: proclaim@3.4.4 & others
Recommendation: Check the package code and files for license information
via: serve-index@1.8.0 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.3 & others
Recommendation: Check the package code and files for license information
via: proclaim@3.4.4
Recommendation: Check the package code and files for license information
via: socket.io-stream@0.9.1
Recommendation: Check the package code and files for license information
via: proclaim@3.4.4
Collapse
Expand

12 high severity issues

high
Recommendation: Upgrade to version 3.6.0 or later
via: socket.io@1.7.3
Recommendation: Upgrade to version 3.3.2 or later
via: socket.io-client@1.7.3 & others
Recommendation: None
via: socket.io-client@1.7.3 & others
Recommendation: Upgrade to version 1.1.5 or later
via: socket.io-client@1.7.3 & others
Recommendation: Upgrade to version 0.5.2 or later
via: express@4.15.2
Recommendation: Upgrade to version 1.4.1 or later
via: express@4.15.2
Recommendation: Upgrade to version 2.6.9 or later
via: express@4.15.2 & others
Recommendation: Upgrade to version 6.4.1 or later
via: express@4.15.2
via: proclaim@3.4.4
via: socket.io-client@1.7.3 & others
via: proclaim@3.4.4
via: uuid@3.0.1
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 3.6.1 or later
via: socket.io@1.7.3
Recommendation: Upgrade to version 2.4.0 or later
via: socket.io@1.7.3
Recommendation: Upgrade to version 2.0.0 or later
via: express@4.15.2 & others
Recommendation: Upgrade to version 1.2.3 or later
via: minimist@1.2.0 & others
Recommendation: Upgrade to version 4.19.2 or later
via: express@4.15.2
via: socket.io-client@1.7.3 & others
via: socket.io-client@1.7.3 & others
via: proclaim@3.4.4 & others
via: socket.io-client@1.7.3 & others
via: proclaim@3.4.4
Collapse
Expand

1 low severity issue

low
Recommendation: Upgrade to version 2.6.9 or later
via: express@4.15.2 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
170 Packages, Including:
accepts@1.3.3
accepts@1.3.8
after@0.8.2
array-buffer-byte-length@1.0.1
array-flatten@1.1.1
array-map@0.0.0
array-reduce@0.0.0
arraybuffer.prototype.slice@1.0.3
available-typed-arrays@1.0.7
backo2@1.0.2
balanced-match@1.0.2
base64-arraybuffer@0.1.5
base64id@1.0.0
batch@0.5.3
brace-expansion@1.1.11
buffer-shims@1.0.0
call-bind@1.0.7
component-emitter@1.2.1
concat-map@0.0.1
content-disposition@0.5.2
content-type@1.0.5
cookie-signature@1.0.6
cookie@0.3.1
core-util-is@1.0.3
data-view-buffer@1.0.1
data-view-byte-length@1.0.1
data-view-byte-offset@1.0.0
debug@2.2.0
debug@2.3.3
debug@2.6.1
debug@2.6.9
deep-equal@1.0.1
define-data-property@1.1.4
define-properties@1.2.1
defined@1.0.1
depd@1.1.2
destroy@1.0.4
ee-first@1.1.1
encodeurl@1.0.2
engine.io-client@1.8.3
engine.io-parser@1.3.2
engine.io@1.8.3
es-abstract@1.23.3
es-define-property@1.0.0
es-errors@1.3.0
es-object-atoms@1.0.0
es-set-tostringtag@2.0.3
es-to-primitive@1.2.1
escape-html@1.0.3
etag@1.8.1

N/A

N/A
14 Packages, Including:
arraybuffer.slice@0.0.6
better-assert@1.0.2
blob@0.0.4
callsite@1.0.0
component-bind@1.0.0
component-emitter@1.1.2
component-inherit@0.0.3
indexof@0.0.1
ms@0.7.1
object-component@0.0.3
options@0.0.6
proclaim@3.4.4
socket.io-stream@0.9.1
util-inspect@0.1.8

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
11 Packages, Including:
fs.realpath@1.0.0
glob@7.1.7
inflight@1.0.6
inherits@2.0.3
inherits@2.0.4
minimatch@3.1.2
once@1.4.0
setprototypeof@1.0.2
setprototypeof@1.0.3
setprototypeof@1.1.0
wrappy@1.0.2

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
qs@6.4.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

12
All Dependencies CSV
β“˜ This is a list of godsend 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
express4.15.251.14 kBMIT
prod
4
2
1
js-logger1.3.074.67 kBMIT
prod
minimist1.2.07.54 kBMIT
prod
1
1
proclaim3.4.437.48 kBUNKNOWN
prod
3
2
2
readable-stream2.2.622.66 kBMIT
prod
serve-index1.8.061.79 kBMIT
prod
1
1
1
1
socket.io-client1.7.3213.31 kBMIT
prod
14
5
5
1
socket.io-stream0.9.156.76 kBUNKNOWN
prod
3
1
1
1
socket.io1.7.319.65 kBMIT
prod
14
6
7
1
tape4.6.321.09 kBMIT
prod
1
1
toposort1.0.35.23 kBMIT
prod
uuid3.0.17.03 kBMIT
prod
1

Visualizations