Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 29, 2024 via pnpm

image-resizer 1.3.0

On-the-fly image resizing and optimization using node and sharp (libvips). Heroku ready!
Package summary
Share
68
issues
16
critical severity
vulnerability
1
license
15
33
high severity
vulnerability
16
license
9
meta
8
8
moderate severity
vulnerability
8
11
low severity
vulnerability
1
license
10
11
licenses
141
MIT
15
N/A
9
ISC
16
other licenses
BSD
6
Apache-2.0
3
BSD-3-Clause
2
Apache 2.0
1
+ 4 more
Package created
18 May 2014
Version published
11 Oct 2015
Maintainers
1
Total deps
181
Direct deps
15
License
MIT

Issues

68

16 critical severity issues

critical
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@2.4.2
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: sharp@0.11.4
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: map-stream@0.1.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: request@2.34.0
Recommendation: Check the package code and files for license information
via: twit@1.1.20
Recommendation: Check the package code and files for license information
via: aws-sdk@2.0.31
Collapse
Expand

33 high severity issues

high
Recommendation: Upgrade to version 6.0.4 or later
via: request@2.34.0
Recommendation: Upgrade to version 2.814.0 or later
via: aws-sdk@2.0.31
Recommendation: Upgrade to version 1.0.0 or later
via: request@2.34.0
Recommendation: Upgrade to version 3.1.3 or later
via: request@2.34.0
Recommendation: Upgrade to version 1.0.0 or later
via: request@2.34.0
Recommendation: Upgrade to version 3.0.2 or later
via: glob@3.2.11
Recommendation: Upgrade to version 1.4.1 or later
via: request@2.34.0
Recommendation: Upgrade to version 4.2.1 or later
via: request@2.34.0
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@2.4.2
Recommendation: Upgrade to version 0.32.6 or later
via: sharp@0.11.4
Recommendation: Upgrade to version 9.0.1 or later
via: request@2.34.0
Recommendation: Upgrade to version 3.0.1 or later
via: image-type@2.1.0
Recommendation: None
via: request@2.34.0
Recommendation: Upgrade to version 6.2.4 or later
via: request@2.34.0
Recommendation: Upgrade to version 3.0.5 or later
via: glob@3.2.11
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@2.4.2
Recommendation: Validate that the package complies with your license policy
via: request@2.34.0
Recommendation: Validate that the package complies with your license policy
via: request@2.34.0
Recommendation: Validate that the package complies with your license policy
via: glob@3.2.11
Recommendation: Validate that the package complies with your license policy
via: request@2.34.0
Recommendation: Validate that the package complies with your license policy
via: request@2.34.0
Recommendation: Validate that the package complies with your license policy
via: request@2.34.0
Recommendation: Validate that the package complies with your license policy
via: aws-sdk@2.0.31
Recommendation: Validate that the package complies with your license policy
via: request@2.34.0
Recommendation: Read and validate the license terms
via: image-type@2.1.0
via: request@2.34.0
via: request@2.34.0
via: request@2.34.0
via: request@2.34.0
via: glob@3.2.11
via: request@2.34.0
via: request@2.34.0
via: request@2.34.0
Collapse
Expand

8 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@2.4.2
Recommendation: Upgrade to version 0.6.0 or later
via: request@2.34.0
Recommendation: Upgrade to version 1.5.5 or later
via: sharp@0.11.4
Recommendation: Upgrade to version 0.5.0 or later
via: aws-sdk@2.0.31
Recommendation: Upgrade to version 0.30.5 or later
via: sharp@0.11.4
Recommendation: None
via: request@2.34.0
Recommendation: Upgrade to version 2.68.0 or later
via: request@2.34.0
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@2.4.2
Collapse
Expand

11 low severity issues

low
Recommendation: Upgrade to version 4.17.5 or later
via: lodash@2.4.2
Recommendation: Read and validate the license terms
via: request@2.34.0
Recommendation: Read and validate the license terms
via: request@2.34.0
Recommendation: Read and validate the license terms
via: glob@3.2.11
Recommendation: Read and validate the license terms
via: request@2.34.0
Recommendation: Read and validate the license terms
via: request@2.34.0
Recommendation: Read and validate the license terms
via: request@2.34.0
Recommendation: Read and validate the license terms
via: aws-sdk@2.0.31
Recommendation: Read and validate the license terms
via: request@2.34.0
Recommendation: Read and validate the license terms
via: image-type@2.1.0
Recommendation: Read and validate the license terms
via: image-type@2.1.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
141 Packages, Including:
accepts@1.3.8
ansi-regex@1.1.1
ansi-styles@2.2.1
array-find-index@1.0.2
array-flatten@1.1.1
async@0.9.2
basic-auth@2.0.1
bluebird@3.7.2
body-parser@1.20.2
bytes@3.1.2
call-bind@1.0.7
camelcase-keys@2.1.0
camelcase@2.1.1
chalk@1.0.0
color-name@1.1.4
color-string@0.3.0
color@0.10.1
commander@2.20.3
concat-stream@1.4.11
content-disposition@0.5.4
content-type@1.0.5
cookie-signature@1.0.6
cookie@0.5.0
core-util-is@1.0.3
currently-unhandled@0.4.1
debug@2.6.9
decamelize@1.2.0
define-data-property@1.1.4
depd@2.0.0
destroy@1.2.0
ee-first@1.1.1
encodeurl@1.0.2
error-ex@1.3.2
errorhandler@1.5.1
es-define-property@1.0.0
es-errors@1.3.0
escape-html@1.0.3
escape-string-regexp@1.0.5
etag@1.8.1
express@4.18.3
file-type@3.9.0
finalhandler@1.2.0
find-up@1.1.2
form-data@0.1.4
forwarded@0.2.0
fresh@0.5.2
function-bind@1.1.2
get-intrinsic@1.2.4
get-stdin@4.0.1
gopd@1.0.1

N/A

N/A
15 Packages, Including:
asn1@0.1.11
assert-plus@0.1.5
aws-sign2@0.5.0
color-convert@0.5.3
combined-stream@0.0.7
ctype@0.5.3
delayed-stream@0.0.5
forever-agent@0.5.2
map-stream@0.1.0
mime@1.2.11
oauth-sign@0.3.0
qs@0.6.6
tunnel-agent@0.3.0
twit@1.1.20
xml2js@0.2.6

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
graceful-fs@4.2.11
hosted-git-info@2.8.9
inherits@2.0.4
json-stringify-safe@5.0.1
lru-cache@2.7.3
semver@5.7.2
setprototypeof@1.2.0
sigmund@1.0.1
signal-exit@3.0.7

BSD

Invalid
Not OSI Approved
6 Packages, Including:
boom@0.4.2
cryptiles@0.2.2
glob@3.2.11
hawk@1.0.0
hoek@0.9.1
sntp@0.2.4

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
3 Packages, Including:
sharp@0.11.4
spdx-correct@3.2.0
validate-npm-package-license@3.0.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
qs@6.11.0
tough-cookie@4.1.3

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
aws-sdk@2.0.31

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
normalize-package-data@2.5.0

Apache, Version 2.0

Invalid
Not OSI Approved
1 Packages, Including:
request@2.34.0

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

15
All Dependencies CSV
β“˜ This is a list of image-resizer 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
aws-sdk2.0.31231.3 kBApache 2.0
prod
1
2
1
1
chalk1.0.04.58 kBMIT
prod
commander2.20.318.26 kBMIT
prod
concat-stream1.4.113.53 kBMIT
prod
errorhandler1.5.15.75 kBMIT
prod
express4.18.3209.05 kBMIT
prod
glob3.2.1116.2 kBBSD
prod
4
1
image-type2.1.02.47 kBMIT
prod
2
2
lodash2.4.2192.11 kBMIT
prod
1
2
2
1
map-stream0.1.04.93 kBUNKNOWN
prod
1
mkdirp0.5.62.95 kBMIT
prod
morgan1.10.09.37 kBMIT
prod
request2.34.021.33 kBApache, Version 2.0
prod
11
22
3
6
sharp0.11.4423.83 kBApache-2.0
prod
1
1
2
twit1.1.2052.85 kBUNKNOWN
prod
1

Visualizations