Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 30, 2024 via pnpm

heroku 8.4.2

CLI to interact with Heroku
Package summary
Share
21
issues
2
critical severity
license
2
14
high severity
vulnerability
2
license
1
meta
11
2
moderate severity
vulnerability
2
3
low severity
vulnerability
1
license
2
12
licenses
381
MIT
54
ISC
29
Apache-2.0
28
other licenses
BSD-3-Clause
10
BSD-2-Clause
7
0BSD
3
N/A
2
+ 5 more
Package created
20 Jan 2012
Version published
31 Aug 2023
Maintainers
46
Total deps
492
Direct deps
67
License
ISC

Issues

21

2 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: @heroku-cli/plugin-container-registry-v5@8.11.1
Recommendation: Check the package code and files for license information
via: valid-url@1.0.9
Collapse
Expand

14 high severity issues

high
Recommendation: Upgrade to version 4.1.1 or later
via: @heroku-cli/plugin-addons-v5@8.11.1 & others
Recommendation: Upgrade to version 0.6.1 or later
via: @heroku-cli/plugin-pg-v5@8.11.1
Recommendation: Validate that the package complies with your license policy
via: @heroku-cli/plugin-ps-exec@2.4.0
via: @heroku-cli/command@9.0.2 & others
via: @oclif/plugin-legacy@1.3.6
via: @heroku-cli/command@9.0.2 & others
via: @heroku-cli/plugin-redis-v5@8.11.1
via: @heroku-cli/command@9.0.2 & others
via: @heroku-cli/plugin-redis-v5@8.11.1
via: @heroku-cli/plugin-pg-v5@8.11.1 & others
via: @heroku-cli/plugin-pg-v5@8.11.1
via: uuid@3.3.2
via: @heroku-cli/plugin-ps-exec@2.4.0
via: @oclif/plugin-plugins@2.4.3
Collapse
Expand

2 moderate severity issues

moderate
Recommendation: Upgrade to version 11.8.5 or later
via: @heroku-cli/plugin-addons-v5@8.11.1 & others
Recommendation: Upgrade to version 5.7.2 or later
via: @heroku-cli/command@9.0.2 & others
Collapse
Expand

3 low severity issues

low
Recommendation: Upgrade to version 4.3.1 or later
via: @heroku-cli/command@9.0.2 & others
Recommendation: Read and validate the license terms
via: edit-string@1.1.6
Recommendation: Read and validate the license terms
via: @heroku-cli/plugin-ps-exec@2.4.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
381 Packages, Including:
@babel/runtime@7.24.1
@cspotcode/source-map-support@0.8.1
@heroku-cli/notifications@1.2.4
@heroku-cli/plugin-ci-v5@8.11.1
@heroku-cli/plugin-ps@8.1.7
@heroku-cli/plugin-run@8.1.4
@heroku-cli/schema@1.0.25
@heroku/buildpack-registry@1.0.1
@heroku/eventsource@1.0.7
@heroku/socksv5@0.0.9
@jridgewell/resolve-uri@3.1.2
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.9
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@oclif/color@0.1.2
@oclif/color@1.0.13
@oclif/command@1.8.36
@oclif/config@1.18.16
@oclif/config@1.18.17
@oclif/core@1.26.2
@oclif/core@2.15.0
@oclif/errors@1.3.6
@oclif/help@1.0.15
@oclif/parser@3.8.17
@oclif/plugin-commands@2.2.2
@oclif/plugin-help@5.2.20
@oclif/plugin-legacy@1.3.6
@oclif/plugin-not-found@2.3.16
@oclif/plugin-plugins@2.4.3
@oclif/plugin-update@3.1.10
@oclif/plugin-version@1.3.10
@oclif/plugin-warn-if-update-available@2.0.29
@oclif/plugin-which@2.2.8
@oclif/screen@1.0.4
@oclif/screen@3.0.8
@sindresorhus/is@0.14.0
@sindresorhus/is@0.7.0
@szmarczak/http-timer@1.1.2
@tsconfig/node10@1.0.11
@tsconfig/node12@1.0.11
@tsconfig/node14@1.0.3
@tsconfig/node16@1.0.4
@types/cli-progress@3.11.5
@types/keyv@3.1.4
@types/node@20.11.30
@types/responselike@1.0.3
@types/shimmer@1.0.5
@xmldom/xmldom@0.8.10

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
54 Packages, Including:
@heroku-cli/color@1.1.14
@heroku-cli/command@8.5.0
@heroku-cli/command@9.0.2
@heroku-cli/heroku-exec-util@0.7.6
@heroku-cli/plugin-addons-v5@8.11.1
@heroku-cli/plugin-addons@1.2.31
@heroku-cli/plugin-apps-v5@8.11.1
@heroku-cli/plugin-certs-v5@8.11.1
@heroku-cli/plugin-container-registry-v5@8.11.1
@heroku-cli/plugin-orgs-v5@8.11.1
@heroku-cli/plugin-pg-v5@8.11.1
@heroku-cli/plugin-ps-exec@2.4.0
@heroku-cli/plugin-redis-v5@8.11.1
@heroku-cli/plugin-run-v5@8.11.1
@heroku-cli/plugin-spaces@8.11.1
@oclif/linewrap@1.0.0
abbrev@1.1.1
at-least-node@1.0.0
chownr@1.1.4
cli-width@2.2.1
cli-width@3.0.0
fastq@1.17.1
fs.realpath@1.0.0
glob-parent@5.1.2
glob@7.2.3
graceful-fs@4.2.11
heroku-cli-util@8.0.12
heroku@8.4.2
http-call@5.3.0
inflight@1.0.6
inherits@2.0.4
isexe@2.0.0
json-stringify-safe@5.0.1
log-chopper@1.0.2
lru-cache@6.0.0
make-error@1.3.6
minimatch@3.1.2
minimatch@5.1.6
mute-stream@0.0.7
mute-stream@0.0.8
netrc-parser@3.1.6
nopt@4.0.3
once@1.4.0
osenv@0.1.5
rimraf@2.6.3
rimraf@2.7.1
semver@5.6.0
semver@7.6.0
signal-exit@3.0.7
smooth-progress@1.1.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
29 Packages, Including:
@opentelemetry/api-logs@0.41.2
@opentelemetry/api@1.8.0
@opentelemetry/context-async-hooks@1.22.0
@opentelemetry/core@1.15.2
@opentelemetry/core@1.22.0
@opentelemetry/exporter-trace-otlp-http@0.41.2
@opentelemetry/instrumentation@0.41.2
@opentelemetry/otlp-exporter-base@0.41.2
@opentelemetry/otlp-transformer@0.41.2
@opentelemetry/propagator-b3@1.22.0
@opentelemetry/propagator-jaeger@1.22.0
@opentelemetry/resources@1.15.2
@opentelemetry/resources@1.22.0
@opentelemetry/sdk-logs@0.41.2
@opentelemetry/sdk-metrics@1.15.2
@opentelemetry/sdk-trace-base@1.15.2
@opentelemetry/sdk-trace-base@1.22.0
@opentelemetry/sdk-trace-node@1.22.0
@opentelemetry/semantic-conventions@1.15.2
@opentelemetry/semantic-conventions@1.22.0
ejs@3.1.9
filelist@1.0.4
human-signals@2.1.0
import-in-the-middle@1.4.2
jake@10.8.7
rxjs@6.6.7
rxjs@7.8.1
tunnel-agent@0.6.0
typescript@5.4.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
10 Packages, Including:
bcrypt-pbkdf@1.0.2
diff@4.0.2
duplexer3@0.1.5
filesize@4.2.1
filesize@6.4.0
ieee754@1.2.1
printf@0.3.0
source-map@0.5.7
sprintf-js@1.0.3
sprintf-js@1.1.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
7 Packages, Including:
dotenv@16.4.5
esprima@4.0.1
http-cache-semantics@3.8.1
http-cache-semantics@4.1.1
shimmer@1.2.1
webidl-conversions@3.0.1
yarn@1.22.22

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
3 Packages, Including:
password-prompt@1.1.3
tslib@1.14.1
tslib@2.6.2

N/A

N/A
2 Packages, Including:
heroku-container-registry@4.99.0
valid-url@1.0.9

(MIT OR CC0-1.0)

Public Domain
2 Packages, Including:
type-fest@0.21.3
type-fest@0.3.1

Do What The F*ck You Want To Public License

Permissive
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
sublicense
distribute
modify
Cannot
Must
rename
1 Packages, Including:
edit-string@1.1.6

BSD / GPL

Invalid
Not OSI Approved
1 Packages, Including:
keypair@1.0.4

(BSD-3-Clause OR GPL-2.0)

Permissive
1 Packages, Including:
node-forge@1.3.0

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

67
All Dependencies CSV
β“˜ This is a list of heroku 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@heroku-cli/color1.1.141.93 kBISC
prod
@heroku-cli/command9.0.214.86 kBISC
prod
3
1
1
@heroku-cli/notifications1.2.4146.37 kBMIT
prod
@heroku-cli/plugin-addons-v58.11.174.78 kBISC
prod
1
2
@heroku-cli/plugin-apps-v58.11.1180.28 kBISC
prod
4
2
1
@heroku-cli/plugin-certs-v58.11.159.9 kBISC
prod
1
2
@heroku-cli/plugin-ci-v58.11.135.03 kBMIT
prod
4
2
1
@heroku-cli/plugin-container-registry-v58.11.131.1 kBISC
prod
1
2
2
1
@heroku-cli/plugin-orgs-v58.11.156.05 kBISC
prod
4
2
1
@heroku-cli/plugin-pg-v58.11.1295.68 kBISC
prod
5
2
1
@heroku-cli/plugin-ps-exec2.4.03.3 kBISC
prod
4
2
1
@heroku-cli/plugin-ps8.1.75.56 kBMIT
prod
3
1
1
@heroku-cli/plugin-redis-v58.11.145.77 kBISC
prod
3
2
@heroku-cli/plugin-run8.1.413.58 kBMIT
prod
3
1
1
@heroku-cli/plugin-spaces8.11.1113.19 kBISC
prod
4
2
1
@heroku-cli/schema1.0.2517.8 kBMIT
prod
@heroku/buildpack-registry1.0.14.72 kBMIT
prod
@heroku/eventsource1.0.7114.71 kBMIT
prod
@oclif/core1.26.273.29 kBMIT
prod
@oclif/core2.15.082.59 kBMIT
prod
@oclif/plugin-commands2.2.2101.35 kBMIT
prod
@oclif/plugin-help5.2.202.41 kBMIT
prod
@oclif/plugin-legacy1.3.64.47 kBMIT
prod
3
1
1
@oclif/plugin-not-found2.3.162.55 kBMIT
prod
@oclif/plugin-plugins2.4.312.47 kBMIT
prod
2
1
@oclif/plugin-update3.1.109.84 kBMIT
prod
1
1
@oclif/plugin-version1.3.103.03 kBMIT
prod
@oclif/plugin-warn-if-update-available2.0.293.95 kBMIT
prod
1
1
@oclif/plugin-which2.2.82.76 kBMIT
prod
@opentelemetry/api1.8.01.15 MBApache-2.0
prod peer
@opentelemetry/exporter-trace-otlp-http0.41.213.16 kBApache-2.0
prod
@opentelemetry/instrumentation0.41.241.25 kBApache-2.0
prod
1
1
@opentelemetry/resources1.22.0490.86 kBApache-2.0
prod
@opentelemetry/sdk-trace-base1.22.0748.04 kBApache-2.0
prod
@opentelemetry/sdk-trace-node1.22.031.01 kBApache-2.0
prod
@opentelemetry/semantic-conventions1.22.01.58 MBApache-2.0
prod
ansi-escapes3.2.03.44 kBMIT
prod
async-file2.0.25.8 kBMIT
prod
chalk2.4.29.63 kBMIT
prod
date-fns2.30.0682.42 kBMIT
prod
debug4.1.121.26 kBMIT
prod
1
1
dotenv16.4.577.22 kBBSD-2-Clause
prod
edit-string1.1.61.27 kBWTFPL
prod
1
1
execa5.1.114.15 kBMIT
prod
foreman3.0.119.58 kBMIT
prod
1
1
fs-extra7.0.131.33 kBMIT
prod
github-url-to-object4.0.65.67 kBMIT
prod
got9.6.024.07 kBMIT
prod
1
heroku-cli-util8.0.1223.66 kBISC
prod
1
2
http-call5.3.08.27 kBISC
prod
1
1
inquirer7.3.322.32 kBMIT
prod
lodash4.17.21311.49 kBMIT
prod
netrc-parser3.1.63.86 kBISC
prod
1
node-fetch2.7.043.6 kBMIT
prod
phoenix1.7.11105.38 kBMIT
prod
rollbar2.26.44 MBMIT
prod
semver5.6.016.16 kBISC
prod
1
shell-escape0.2.01.39 kBMIT
prod
shell-quote1.8.115.23 kBMIT
prod
tmp0.0.338.42 kBMIT
prod
true-myth2.2.3158.91 kBMIT
prod
tslib1.14.17.43 kB0BSD
prod
urijs1.19.1152.16 kBMIT
prod
uuid3.3.212.61 kBMIT
prod
1
valid-url1.0.95 kBUNKNOWN
prod
1
validator13.11.0176.41 kBMIT
prod
ws6.2.224.25 kBMIT
prod

Visualizations