Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 1, 2024 via pnpm
Package summary
Share
11
issues
2
critical severity
vulnerability
2
6
high severity
vulnerability
3
meta
3
2
moderate severity
vulnerability
2
1
low severity
vulnerability
1
9
licenses
119
MIT
12
ISC
2
BSD-2-Clause
8
other licenses
BSD-3-Clause
2
Apache-2.0
2
Unlicense
1
(WTFPL OR MIT)
1
+ 2 more
Package created
16 Oct 2016
Version published
31 May 2019
Maintainers
1
Total deps
141
Direct deps
11
License
Unlicense

Issues

11

2 critical severity issues

critical
Recommendation: Upgrade to version 5.0.0 or later
via: md-to-pdf@2.7.1
Recommendation: Upgrade to version 5.0.0 or later
via: md-to-pdf@2.7.1
Collapse
Expand

6 high severity issues

high
Recommendation: Upgrade to version 4.0.10 or later
via: marked@0.6.2
Recommendation: Upgrade to version 4.0.10 or later
via: marked@0.6.2
Recommendation: Upgrade to version 3.0.5 or later
via: serve-handler@6.0.1
via: highlight.js@9.15.8
via: puppeteer@1.17.0
via: puppeteer@1.17.0
Collapse
Expand

2 moderate severity issues

moderate
Recommendation: Upgrade to version 10.4.1 or later
via: highlight.js@9.15.8
Recommendation: Upgrade to version 9.18.2 or later
via: highlight.js@9.15.8
Collapse
Expand

1 low severity issue

low
Recommendation: Upgrade to version 0.7.0 or later
via: marked@0.6.2
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
119 Packages, Including:
@samverschueren/stream-to-observable@0.3.1
agent-base@4.3.0
ansi-escapes@3.2.0
ansi-regex@2.1.1
ansi-regex@3.0.1
ansi-styles@2.2.1
ansi-styles@3.2.1
any-observable@0.3.0
arg@4.1.0
argparse@1.0.10
async-each@1.0.6
async-limiter@1.0.1
balanced-match@1.0.2
binary-extensions@2.3.0
brace-expansion@1.1.11
braces@3.0.2
buffer-crc32@0.2.13
buffer-from@1.1.2
bytes@3.0.0
chalk@1.1.3
chalk@2.4.2
chokidar@3.0.0
cli-cursor@2.1.0
cli-truncate@0.2.1
code-point-at@1.1.0
color-convert@1.9.3
color-name@1.1.3
concat-map@0.0.1
concat-stream@1.6.2
content-disposition@0.5.2
core-util-is@1.0.3
date-fns@1.30.1
debug@2.6.9
debug@3.2.7
debug@4.3.4
elegant-spinner@1.0.1
es6-promise@4.2.8
es6-promisify@5.0.0
escape-string-regexp@1.0.5
extend-shallow@2.0.1
fast-url-parser@1.1.3
fd-slicer@1.1.0
figures@1.7.0
figures@2.0.0
fill-range@7.0.1
fsevents@2.3.3
get-port@5.0.0
gray-matter@4.0.2
has-ansi@2.0.0
has-flag@3.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
12 Packages, Including:
anymatch@3.1.3
fs.realpath@1.0.0
glob-parent@5.1.2
glob@7.2.3
inflight@1.0.6
inherits@2.0.4
minimatch@3.0.4
minimatch@3.1.2
once@1.4.0
rimraf@2.7.1
signal-exit@3.0.7
wrappy@1.0.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
esprima@4.0.1
extract-zip@1.7.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
highlight.js@9.15.8
sprintf-js@1.0.3

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
puppeteer@1.17.0
rxjs@6.6.7

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
md-to-pdf@2.7.1

(WTFPL OR MIT)

Permissive
1 Packages, Including:
path-is-inside@1.0.2

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
1 Packages, Including:
tslib@1.14.1

(MIT OR CC0-1.0)

Public Domain
1 Packages, Including:
type-fest@0.3.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

11
All Dependencies CSV
β“˜ This is a list of md-to-pdf 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
arg4.1.05.12 kBMIT
prod
chalk2.4.29.63 kBMIT
prod
chokidar3.0.023.21 kBMIT
prod
get-port5.0.02.87 kBMIT
prod
gray-matter4.0.211.44 kBMIT
prod
highlight.js9.15.8366.66 kBBSD-3-Clause
prod
1
2
iconv-lite0.4.24180.9 kBMIT
prod
listr0.14.37.68 kBMIT
prod peer
marked0.6.223.98 kBMIT
prod
2
1
puppeteer1.17.0129.99 kBApache-2.0
prod
2
serve-handler6.0.113.85 kBMIT
prod
1

Visualizations