Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 1, 2024 via pnpm
Package summary
Share
12
issues
10
high severity
vulnerability
1
license
1
meta
8
2
low severity
license
2
8
licenses
265
MIT
32
ISC
2
Apache-2.0
5
other licenses
(MIT OR Apache-2.0)
1
BSD-2-Clause
1
BSD-3-Clause
1
CC-BY-3.0
1
+ 1 more
Package created
4 Jul 2013
Version published
6 May 2019
Maintainers
2
Total deps
304
Direct deps
4
License
MIT

Issues

12

10 high severity issues

high
Recommendation: Upgrade to version 5.1.2 or later
via: glob-watcher@5.0.5 & others
Recommendation: Read and validate the license terms
via: gulp-cli@2.3.0
via: glob-watcher@5.0.5
via: gulp-cli@2.3.0 & others
via: glob-watcher@5.0.5
via: glob-watcher@5.0.5
via: glob-watcher@5.0.5 & others
via: glob-watcher@5.0.5 & others
via: glob-watcher@5.0.5 & others
via: glob-watcher@5.0.5 & others
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: gulp-cli@2.3.0
Recommendation: Read and validate the license terms
via: gulp-cli@2.3.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
265 Packages, Including:
ansi-colors@1.1.0
ansi-gray@0.1.1
ansi-regex@2.1.1
ansi-wrap@0.1.0
append-buffer@1.0.2
archy@1.0.0
arr-diff@4.0.0
arr-filter@1.1.2
arr-flatten@1.1.0
arr-map@2.0.2
arr-union@3.1.0
array-each@1.0.1
array-initial@1.1.0
array-last@1.3.0
array-slice@1.1.0
array-sort@1.0.0
array-unique@0.3.2
assign-symbols@1.0.0
async-done@1.3.2
async-each@1.0.6
async-settle@1.0.0
bach@1.2.0
balanced-match@1.0.2
base@0.11.2
binary-extensions@1.13.1
bindings@1.5.0
brace-expansion@1.1.11
braces@2.3.2
buffer-equal@1.0.1
buffer-from@1.1.2
cache-base@1.0.1
call-bind@1.0.7
camelcase@3.0.0
chokidar@2.1.8
class-utils@0.3.6
clone-buffer@1.0.0
clone-stats@1.0.0
clone@2.1.2
cloneable-readable@1.1.3
code-point-at@1.1.0
collection-map@1.0.0
collection-visit@1.0.0
component-emitter@1.3.1
concat-map@0.0.1
concat-stream@1.6.2
convert-source-map@1.9.0
copy-descriptor@0.1.1
copy-props@2.0.5
core-util-is@1.0.3
debug@2.6.9

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
32 Packages, Including:
anymatch@2.0.0
cliui@3.2.0
color-support@1.1.3
d@1.0.2
es5-ext@0.10.64
es6-symbol@3.1.4
es6-weak-map@2.0.3
esniff@2.0.1
ext@1.7.0
fs.realpath@1.0.0
get-caller-file@1.0.3
glob-parent@3.1.0
glob@7.2.3
graceful-fs@4.2.11
hosted-git-info@2.8.9
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
isexe@2.0.0
minimatch@3.1.2
next-tick@1.1.0
once@1.4.0
remove-trailing-separator@1.1.0
require-main-filename@1.0.1
semver@5.7.2
set-blocking@2.0.0
type@2.7.2
which-module@1.0.0
which@1.3.1
wrappy@1.0.2
y18n@3.2.2
yargs-parser@5.0.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
spdx-correct@3.2.0
validate-npm-package-license@3.0.4

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
normalize-package-data@2.5.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
source-map@0.5.7

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

4
All Dependencies CSV
β“˜ This is a list of gulp 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
glob-watcher5.0.54.5 kBMIT
prod
8
gulp-cli2.3.017.12 kBMIT
prod
6
2
undertaker1.3.07.9 kBMIT
prod
1
vinyl-fs3.0.313.51 kBMIT
prod
1

Visualizations

Frequently Asked Questions

What does gulp do?

Gulp is a dynamic toolkit serving as a handy automation platform, perfect for executing painful or time-consuming tasks in your development workflow. It's a platform-agnostic system, integrated with all major IDEs, making it usable with different platforms, including PHP, .NET, Node.js, Java, and others. Gulp's strong ecosystem leverages over 2000 curated plugins for streaming file transformations, supporting a wide array of tasks. Despite its extensive capabilities, Gulp maintains simplicity through its minimal API surface, making it easy to learn and straightforward to use.

How do you use gulp?

Gulp is conveniently accessible and smoothly fits into your development processes. To start using Gulp:

  1. Install it via Node Package Manager (npm) following the Quick Start guide.
  2. Create a gulpfile.js in your project root, which serves as a control center for all your Gulp tasks.

A gulpfile.js may look something like this:

var gulp = require('gulp');
var less = require('gulp-less');
var babel = require('gulp-babel');
var concat = require('gulp-concat');
var uglify = require('gulp-uglify');
var rename = require('gulp-rename');
var cleanCSS = require('gulp-clean-css');
var del = require('del');

var paths = {
  styles: {
    src: 'src/styles/**/*.less',
    dest: 'assets/styles/'
  },
  scripts: {
    src: 'src/scripts/**/*.js',
    dest: 'assets/scripts/'
  }
};

function clean() {
  // Deletes previously built assets
  return del([ 'assets' ]);
}

function styles() {
  // Compiles less sources, minifies compiled CSS and renames output file
  return gulp.src(paths.styles.src)
    .pipe(less())
    .pipe(cleanCSS())
    .pipe(rename({ basename: 'main', suffix: '.min' }))
    .pipe(gulp.dest(paths.styles.dest));
}

function scripts() {
  // Compiles JavaScript sources, minifies compiled script and concatenates all to a single file
  return gulp.src(paths.scripts.src, { sourcemaps: true })
    .pipe(babel())
    .pipe(uglify())
    .pipe(concat('main.min.js'))
    .pipe(gulp.dest(paths.scripts.dest));
}

// Registers tasks, sets up watchers and exports a build function
var build = gulp.series(clean, gulp.parallel(styles, scripts));
exports.clean = clean;
exports.styles = styles;
exports.scripts = scripts;
exports.build = build;
exports.default = build;

With the Gulpfile set up, use the command line interface to run specific tasks. For instance, use 'gulp scripts' to run the scripts task. A task can be kept running to automatically rerun any time changes are made on the source files by running 'gulp watch'.

Where are the gulp docs?

The official Gulp documentation is accessible on the Gulp website. You can start with the Getting Started guide to hit the ground running. For more detailed information about the Gulp API and concepts, you can proceed to the API docs.