Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 19, 2024 via pnpm

gulp 3.8.4

The streaming build system
Package summary
Share
39
issues
4
critical severity
vulnerability
2
license
2
20
high severity
vulnerability
6
license
8
meta
6
5
moderate severity
vulnerability
5
10
low severity
vulnerability
1
license
9
9
licenses
114
MIT
14
ISC
6
BSD
8
other licenses
N/A
2
Apache-2.0
2
MIT/X11
1
BSD-2-Clause
1
+ 2 more
Package created
4 Jul 2013
Version published
27 Jun 2014
Maintainers
2
Total deps
142
Direct deps
12
License
UNKNOWN

Issues

39

4 critical severity issues

critical
Recommendation: Upgrade to version 4.17.12 or later
via: liftoff@0.11.3 & others
Recommendation: Upgrade to version 0.2.4 or later
via: liftoff@0.11.3 & others
Recommendation: Check the package code and files for license information
via: liftoff@0.11.3
Recommendation: Check the package code and files for license information
via: vinyl-fs@0.3.14
Collapse
Expand

20 high severity issues

high
Recommendation: Upgrade to version 4.3.2 or later
via: gulp-util@2.2.20 & others
Recommendation: Upgrade to version 3.0.2 or later
via: liftoff@0.11.3 & others
Recommendation: Upgrade to version 4.17.11 or later
via: liftoff@0.11.3 & others
Recommendation: Upgrade to version 3.0.1 or later
via: gulp-util@2.2.20
Recommendation: Upgrade to version 3.0.5 or later
via: liftoff@0.11.3 & others
Recommendation: Upgrade to version 4.17.21 or later
via: liftoff@0.11.3 & others
Recommendation: Validate that the package complies with your license policy
via: gulp-util@2.2.20
Recommendation: Validate that the package complies with your license policy
via: vinyl-fs@0.3.14
Recommendation: Validate that the package complies with your license policy
via: liftoff@0.11.3
Recommendation: Validate that the package complies with your license policy
via: vinyl-fs@0.3.14
Recommendation: Validate that the package complies with your license policy
via: gulp-util@2.2.20 & others
Recommendation: Validate that the package complies with your license policy
via: vinyl-fs@0.3.14
Recommendation: Validate that the package complies with your license policy
via: archy@0.0.2
Recommendation: Read and validate the license terms
via: gulp-util@2.2.20
via: vinyl-fs@0.3.14
via: gulp-util@2.2.20
via: vinyl-fs@0.3.14
via: liftoff@0.11.3
via: vinyl-fs@0.3.14
via: vinyl-fs@0.3.14
Collapse
Expand

5 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: liftoff@0.11.3 & others
Recommendation: Upgrade to version 2.0.2 or later
via: liftoff@0.11.3
Recommendation: Upgrade to version 4.17.21 or later
via: liftoff@0.11.3 & others
Recommendation: Upgrade to version 0.2.1 or later
via: liftoff@0.11.3 & others
Recommendation: Upgrade to version 5.7.2 or later
via: gulp-util@2.2.20 & others
Collapse
Expand

10 low severity issues

low
Recommendation: Upgrade to version 4.17.5 or later
via: liftoff@0.11.3 & others
Recommendation: Read and validate the license terms
via: gulp-util@2.2.20
Recommendation: Read and validate the license terms
via: vinyl-fs@0.3.14
Recommendation: Read and validate the license terms
via: liftoff@0.11.3
Recommendation: Read and validate the license terms
via: vinyl-fs@0.3.14
Recommendation: Read and validate the license terms
via: gulp-util@2.2.20 & others
Recommendation: Read and validate the license terms
via: vinyl-fs@0.3.14
Recommendation: Read and validate the license terms
via: archy@0.0.2
Recommendation: Read and validate the license terms
via: gulp-util@2.2.20
Recommendation: Read and validate the license terms
via: gulp-util@2.2.20
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
114 Packages, Including:
ansi-regex@0.2.1
ansi-styles@1.0.0
ansi-styles@1.1.0
array-find-index@1.0.2
balanced-match@1.0.2
brace-expansion@1.1.11
camelcase-keys@2.1.0
camelcase@2.1.1
chalk@0.4.0
chalk@0.5.1
clone-stats@0.0.1
clone@0.2.0
clone@1.0.4
concat-map@0.0.1
core-util-is@1.0.3
currently-unhandled@0.4.1
dateformat@1.0.12
decamelize@1.2.0
defaults@1.0.4
deprecated@0.0.1
end-of-stream@0.1.5
error-ex@1.3.2
escape-string-regexp@1.0.5
find-index@0.1.1
find-up@1.1.2
findup-sync@0.1.3
first-chunk-stream@1.0.0
function-bind@1.1.2
gaze@0.5.2
get-stdin@4.0.1
glob-stream@3.1.18
glob-watcher@0.0.6
glob2base@0.0.12
globule@0.1.0
gulp-util@2.2.20
gulp@3.8.4
has-ansi@0.1.0
has-color@0.1.7
hasown@2.0.2
indent-string@2.1.0
interpret@0.3.10
is-arrayish@0.2.1
is-core-module@2.13.1
is-finite@1.1.0
is-utf8@0.2.1
isarray@0.0.1
liftoff@0.11.3
load-json-file@1.1.0
lodash._escapehtmlchar@2.4.1
lodash._escapestringchar@2.4.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
14 Packages, Including:
glob@4.5.3
graceful-fs@3.0.12
graceful-fs@4.2.11
hosted-git-info@2.8.9
inflight@1.0.6
inherits@2.0.4
lru-cache@2.7.3
minimatch@2.0.10
natives@1.1.6
once@1.3.3
once@1.4.0
sigmund@1.0.1
signal-exit@3.0.7
wrappy@1.0.2

BSD

Invalid
Not OSI Approved
6 Packages, Including:
duplexer2@0.0.2
glob@3.1.21
glob@3.2.11
graceful-fs@1.2.3
semver@2.3.2
unique-stream@1.0.0

N/A

N/A
2 Packages, Including:
extend@1.2.1
inherits@1.0.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
spdx-correct@3.2.0
validate-npm-package-license@3.0.4

MIT/X11

Invalid
Not OSI Approved
1 Packages, Including:
archy@0.0.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
normalize-package-data@2.5.0

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

12
All Dependencies CSV
β“˜ This is a list of gulp 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
archy0.0.22.18 kBMIT/X11
prod
1
1
chalk0.4.02.47 kBMIT
prod
deprecated0.0.12.44 kBMIT
prod
gulp-util2.2.205.11 kBMIT
prod
6
1
4
interpret0.3.102.64 kBMIT
prod
liftoff0.11.3545.12 kBMIT
prod
3
6
4
2
minimist0.1.06.29 kBMIT
prod
1
1
orchestrator0.3.86.48 kBMIT
prod
pretty-hrtime0.2.22.48 kBMIT
prod
semver2.3.232.4 kBBSD
prod
2
1
1
tildify0.2.0806 BMIT
prod
vinyl-fs0.3.144.64 kBMIT
prod
2
11
2
4

Visualizations

Frequently Asked Questions

What does gulp do?

Gulp is a dynamic toolkit serving as a handy automation platform, perfect for executing painful or time-consuming tasks in your development workflow. It's a platform-agnostic system, integrated with all major IDEs, making it usable with different platforms, including PHP, .NET, Node.js, Java, and others. Gulp's strong ecosystem leverages over 2000 curated plugins for streaming file transformations, supporting a wide array of tasks. Despite its extensive capabilities, Gulp maintains simplicity through its minimal API surface, making it easy to learn and straightforward to use.

How do you use gulp?

Gulp is conveniently accessible and smoothly fits into your development processes. To start using Gulp:

  1. Install it via Node Package Manager (npm) following the Quick Start guide.
  2. Create a gulpfile.js in your project root, which serves as a control center for all your Gulp tasks.

A gulpfile.js may look something like this:

var gulp = require('gulp');
var less = require('gulp-less');
var babel = require('gulp-babel');
var concat = require('gulp-concat');
var uglify = require('gulp-uglify');
var rename = require('gulp-rename');
var cleanCSS = require('gulp-clean-css');
var del = require('del');

var paths = {
  styles: {
    src: 'src/styles/**/*.less',
    dest: 'assets/styles/'
  },
  scripts: {
    src: 'src/scripts/**/*.js',
    dest: 'assets/scripts/'
  }
};

function clean() {
  // Deletes previously built assets
  return del([ 'assets' ]);
}

function styles() {
  // Compiles less sources, minifies compiled CSS and renames output file
  return gulp.src(paths.styles.src)
    .pipe(less())
    .pipe(cleanCSS())
    .pipe(rename({ basename: 'main', suffix: '.min' }))
    .pipe(gulp.dest(paths.styles.dest));
}

function scripts() {
  // Compiles JavaScript sources, minifies compiled script and concatenates all to a single file
  return gulp.src(paths.scripts.src, { sourcemaps: true })
    .pipe(babel())
    .pipe(uglify())
    .pipe(concat('main.min.js'))
    .pipe(gulp.dest(paths.scripts.dest));
}

// Registers tasks, sets up watchers and exports a build function
var build = gulp.series(clean, gulp.parallel(styles, scripts));
exports.clean = clean;
exports.styles = styles;
exports.scripts = scripts;
exports.build = build;
exports.default = build;

With the Gulpfile set up, use the command line interface to run specific tasks. For instance, use 'gulp scripts' to run the scripts task. A task can be kept running to automatically rerun any time changes are made on the source files by running 'gulp watch'.

Where are the gulp docs?

The official Gulp documentation is accessible on the Gulp website. You can start with the Getting Started guide to hit the ground running. For more detailed information about the Gulp API and concepts, you can proceed to the API docs.