Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 22, 2024 via pnpm

image-resizer 0.7.2

On-the-fly image resizing and optimization using node and graphicsmagick. Heroku ready!
Package summary
Share
109
issues
23
critical severity
vulnerability
4
license
19
56
high severity
vulnerability
21
license
17
meta
18
12
moderate severity
vulnerability
11
meta
1
18
low severity
vulnerability
1
license
17
7
licenses
177
MIT
19
N/A
17
ISC
19
other licenses
BSD
15
BSD-3-Clause
2
Apache 2.0
1
Apache, Version 2.0
1
Package created
18 May 2014
Version published
16 Jun 2014
Maintainers
1
Total deps
232
Direct deps
17
License
MIT

Issues

109

23 critical severity issues

critical
Recommendation: Upgrade to version 1.21.1 or later
via: gm@1.14.2
Recommendation: Upgrade to version 4.2.1 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 1.12.1 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@2.4.2
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: gm@1.14.2
Recommendation: Check the package code and files for license information
via: knox@0.8.10
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: map-stream@0.1.0
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9 & others
Recommendation: Check the package code and files for license information
via: twit@1.1.20
Recommendation: Check the package code and files for license information
via: imagemin@0.4.9
Recommendation: Check the package code and files for license information
via: aws-sdk@2.0.31
Recommendation: Check the package code and files for license information
via: knox@0.8.10
Collapse
Expand

56 high severity issues

high
Recommendation: Upgrade to version 6.0.4 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 2.814.0 or later
via: aws-sdk@2.0.31
Recommendation: Upgrade to version 3.2.2 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 1.0.0 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 2.0.0 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 3.1.3 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 1.0.0 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 3.0.2 or later
via: glob@3.2.11
Recommendation: Upgrade to version 1.4.1 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 4.2.1 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 2.6.9 or later
via: gm@1.14.2 & others
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@2.4.2
Recommendation: Upgrade to version 1.0.12 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 3.13.1 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 9.0.1 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 4.4.18 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 2.2.2 or later
via: imagemin@0.4.9
Recommendation: None
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 6.2.4 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 3.0.5 or later
via: glob@3.2.11
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@2.4.2
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9 & others
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9 & others
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9
Recommendation: Validate that the package complies with your license policy
via: glob@3.2.11
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9 & others
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9 & others
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9
Recommendation: Validate that the package complies with your license policy
via: knox@0.8.10
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9 & others
Recommendation: Validate that the package complies with your license policy
via: knox@0.8.10
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9
Recommendation: Validate that the package complies with your license policy
via: aws-sdk@2.0.31
Recommendation: Validate that the package complies with your license policy
via: imagemin@0.4.9 & others
via: imagemin@0.4.9 & others
via: imagemin@0.4.9 & others
via: imagemin@0.4.9
via: imagemin@0.4.9
via: imagemin@0.4.9 & others
via: imagemin@0.4.9 & others
via: imagemin@0.4.9
via: glob@3.2.11
via: imagemin@0.4.9
via: imagemin@0.4.9 & others
via: imagemin@0.4.9
via: imagemin@0.4.9
via: imagemin@0.4.9 & others
via: imagemin@0.4.9 & others
via: static-favicon@2.0.0-alpha
via: imagemin@0.4.9
via: imagemin@0.4.9
via: imagemin@0.4.9
Collapse
Expand

12 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@2.4.2
Recommendation: Upgrade to version 3.3.5 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 3.13.0 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 0.6.0 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 11.8.5 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 2.68.0 or later
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@2.4.2
Recommendation: Upgrade to version 0.5.0 or later
via: aws-sdk@2.0.31 & others
Recommendation: None
via: imagemin@0.4.9 & others
Recommendation: Upgrade to version 6.2.1 or later
via: imagemin@0.4.9
Recommendation: Upgrade to version 4.17.5 or later
via: lodash@2.4.2
via: gm@1.14.2
Collapse
Expand

18 low severity issues

low
Recommendation: Upgrade to version 2.6.9 or later
via: gm@1.14.2 & others
Recommendation: Read and validate the license terms
via: imagemin@0.4.9 & others
Recommendation: Read and validate the license terms
via: imagemin@0.4.9 & others
Recommendation: Read and validate the license terms
via: imagemin@0.4.9
Recommendation: Read and validate the license terms
via: imagemin@0.4.9
Recommendation: Read and validate the license terms
via: imagemin@0.4.9
Recommendation: Read and validate the license terms
via: glob@3.2.11
Recommendation: Read and validate the license terms
via: imagemin@0.4.9 & others
Recommendation: Read and validate the license terms
via: imagemin@0.4.9 & others
Recommendation: Read and validate the license terms
via: imagemin@0.4.9
Recommendation: Read and validate the license terms
via: imagemin@0.4.9
Recommendation: Read and validate the license terms
via: knox@0.8.10
Recommendation: Read and validate the license terms
via: imagemin@0.4.9
Recommendation: Read and validate the license terms
via: imagemin@0.4.9 & others
Recommendation: Read and validate the license terms
via: knox@0.8.10
Recommendation: Read and validate the license terms
via: imagemin@0.4.9
Recommendation: Read and validate the license terms
via: aws-sdk@2.0.31
Recommendation: Read and validate the license terms
via: imagemin@0.4.9 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
177 Packages, Including:
@types/keyv@3.1.4
@types/node@20.12.12
@types/responselike@1.0.3
accepts@1.3.8
adm-zip@0.4.16
ansi-regex@2.1.1
ansi-styles@1.0.0
ansi-styles@2.2.1
argparse@0.1.16
array-flatten@1.1.1
array-parallel@0.1.3
array-series@0.1.5
async@0.9.2
balanced-match@1.0.2
basic-auth@2.0.1
bin-build@0.1.1
bin-check@0.1.5
bin-wrapper@0.3.4
body-parser@1.20.2
brace-expansion@1.1.11
bytes@3.1.2
call-bind@1.0.7
chalk@0.4.0
chalk@1.1.3
coa@0.4.1
commander@2.20.3
concat-map@0.0.1
concat-stream@1.4.11
content-disposition@0.5.4
content-type@1.0.5
cookie-signature@1.0.6
cookie@0.6.0
core-util-is@1.0.3
debug@2.6.9
decompress@0.2.5
define-data-property@1.1.4
depd@2.0.0
destroy@1.2.0
download@0.1.19
duplexer@0.1.2
each-async@0.1.3
ee-first@1.1.1
encodeurl@1.0.2
errorhandler@1.5.1
es-define-property@1.0.0
es-errors@1.3.0
escape-html@1.0.3
escape-string-regexp@1.0.5
etag@1.8.1
exec-buffer@0.1.1

N/A

N/A
19 Packages, Including:
asn1@0.1.11
assert-plus@0.1.5
aws-sign2@0.5.0
colors@0.6.2
combined-stream@0.0.7
ctype@0.5.3
debug@0.7.0
debug@0.7.4
delayed-stream@0.0.5
forever-agent@0.5.2
map-stream@0.1.0
mime@1.2.11
oauth-sign@0.3.0
qs@0.6.6
tunnel-agent@0.3.0
twit@1.1.20
uuid@1.4.2
xml2js@0.2.6
xml2js@0.2.8

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
17 Packages, Including:
abbrev@1.1.1
block-stream@0.0.9
fs.realpath@1.0.0
glob@7.2.3
graceful-fs@3.0.12
inflight@1.0.6
inherits@2.0.4
json-stringify-safe@5.0.1
lru-cache@2.7.3
minimatch@3.1.2
natives@1.1.6
nopt@3.0.6
once@1.4.0
rimraf@2.7.1
setprototypeof@1.2.0
sigmund@1.0.1
wrappy@1.0.2

BSD

Invalid
Not OSI Approved
15 Packages, Including:
boom@0.4.2
cryptiles@0.2.2
esprima@1.0.4
fstream@0.1.31
gifsicle@0.1.7
glob@3.2.11
hawk@1.0.0
hoek@0.9.1
jpegtran-bin@0.2.8
optipng-bin@0.3.11
sax@0.5.8
sax@0.6.1
sntp@0.2.4
stream-counter@0.1.0
tar@0.1.20

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
qs@6.11.0
tough-cookie@4.1.4

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
aws-sdk@2.0.31

Apache, Version 2.0

Invalid
Not OSI Approved
1 Packages, Including:
request@2.34.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

17
All Dependencies CSV
β“˜ This is a list of image-resizer 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
aws-sdk2.0.31231.3 kBApache 2.0
prod
1
2
1
1
chalk0.4.02.47 kBMIT
prod
commander2.20.318.26 kBMIT
prod
concat-stream1.4.113.53 kBMIT
prod
errorhandler1.5.15.75 kBMIT
prod
express4.19.2209.73 kBMIT
prod
glob3.2.1116.2 kBBSD
prod
4
1
gm1.14.223.94 kBMIT
prod
2
1
1
1
imagemin0.4.92.82 kBMIT
prod
15
44
7
13
knox0.8.1013.14 kBMIT
prod
2
3
1
3
lodash2.4.2192.11 kBMIT
prod
1
2
3
map-stream0.1.04.93 kBUNKNOWN
prod
1
mkdirp0.5.62.95 kBMIT
prod optional
morgan1.10.09.37 kBMIT
prod
request2.34.021.33 kBApache, Version 2.0
prod optional
11
22
3
6
static-favicon2.0.0-alpha2.33 kBMIT
prod
1
twit1.1.2052.85 kBUNKNOWN
prod
1

Visualizations