Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Jun 9, 2024 via pnpm

kraken-js 2.5.0

An express-based Node.js web application bootstrapping module.
Package summary
Share
17
issues
9
high severity
license
8
meta
1
8
low severity
license
8
4
licenses
103
MIT
9
ISC
8
Apache 2.0
1
BSD-3-Clause
Package created
15 Nov 2013
Version published
16 Aug 2023
Maintainers
8
Total deps
121
Direct deps
23
License
UNKNOWN

Issues

17

9 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: confit@3.0.0
Recommendation: Validate that the package complies with your license policy
via: express-enrouten@1.3.0
Recommendation: Validate that the package complies with your license policy
via: kraken-js@2.5.0
Recommendation: Validate that the package complies with your license policy
via: lusca@1.7.0
Recommendation: Validate that the package complies with your license policy
via: meddleware@3.0.4
Recommendation: Validate that the package complies with your license policy
via: confit@3.0.0 & others
Recommendation: Validate that the package complies with your license policy
via: shortstop@1.0.2
Recommendation: Validate that the package complies with your license policy
via: confit@3.0.0
via: formidable@1.2.6
Collapse
Expand

8 low severity issues

low
Recommendation: Read and validate the license terms
via: confit@3.0.0
Recommendation: Read and validate the license terms
via: express-enrouten@1.3.0
Recommendation: Read and validate the license terms
via: kraken-js@2.5.0
Recommendation: Read and validate the license terms
via: lusca@1.7.0
Recommendation: Read and validate the license terms
via: meddleware@3.0.4
Recommendation: Read and validate the license terms
via: confit@3.0.0 & others
Recommendation: Read and validate the license terms
via: shortstop@1.0.2
Recommendation: Read and validate the license terms
via: confit@3.0.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
103 Packages, Including:
accepts@1.3.8
array-flatten@1.1.1
async@0.2.10
async@2.6.4
async@3.2.5
balanced-match@1.0.2
basic-auth@2.0.1
bluebird@3.7.2
body-parser@1.20.2
brace-expansion@1.1.11
bytes@3.0.0
bytes@3.1.2
call-bind@1.0.7
caller@1.0.1
caller@1.1.0
compressible@2.0.18
compression@1.7.4
concat-map@0.0.1
content-disposition@0.5.4
content-type@1.0.5
cookie-parser@1.4.6
cookie-signature@1.0.6
cookie-signature@1.0.7
cookie@0.4.1
cookie@0.6.0
core-util-is@1.0.3
debug@2.6.9
debuglog@1.0.1
define-data-property@1.1.4
depd@2.0.0
destroy@1.2.0
ee-first@1.1.1
encodeurl@1.0.2
endgame@1.0.0
es-define-property@1.0.0
es-errors@1.3.0
escape-html@1.0.3
etag@1.8.1
express-session@1.18.0
express@4.19.2
finalhandler@1.2.0
formidable@1.2.6
forwarded@0.2.0
fresh@0.5.2
function-bind@1.1.2
get-intrinsic@1.2.4
gopd@1.0.1
has-property-descriptors@1.0.2
has-proto@1.0.3
has-symbols@1.0.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
fs.realpath@1.0.0
glob@7.2.3
inflight@1.0.6
inherits@2.0.4
minimatch@3.1.2
once@1.4.0
setprototypeof@1.2.0
shortstop-resolve@1.0.3
wrappy@1.0.2

Apache 2.0

Invalid
Not OSI Approved
8 Packages, Including:
confit@3.0.0
express-enrouten@1.3.0
kraken-js@2.5.0
lusca@1.7.0
meddleware@3.0.4
shortstop-handlers@1.1.1
shortstop@1.0.2
shortstop@1.0.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
qs@6.11.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

23
All Dependencies CSV
β“˜ This is a list of kraken-js 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
bluebird3.7.2136.03 kBMIT
prod
body-parser1.20.214.75 kBMIT
prod
caller1.1.02.01 kBMIT
prod
compression1.7.47.64 kBMIT
prod
confit3.0.017.5 kBApache 2.0
prod
3
3
cookie-parser1.4.64.2 kBMIT
prod
core-util-is1.0.31.85 kBMIT
prod
debuglog1.0.11.88 kBMIT
prod
depd2.0.08.18 kBMIT
prod
endgame1.0.02.33 kBMIT
prod
express-enrouten1.3.010.12 kBApache 2.0
prod
1
1
express-session1.18.022.25 kBMIT
prod
express4.19.2209.73 kBMIT
prod peer
formidable1.2.613.31 kBMIT
prod
1
lusca1.7.010.46 kBApache 2.0
prod
1
1
meddleware3.0.410.52 kBApache 2.0
prod
1
1
morgan1.10.09.37 kBMIT
prod
serve-favicon2.5.06.67 kBMIT
prod
serve-static1.15.08.31 kBMIT
prod
shortstop-handlers1.1.16.19 kBApache 2.0
prod
1
1
shortstop-resolve1.0.3958 BISC
prod
shortstop1.0.25.06 kBApache 2.0
prod
1
1
shush1.0.41.96 kBMIT
prod

Visualizations