Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 21, 2024 via pnpm

meshblu 1.30.1

Meshblu IoT network and API
Package summary
Share
35
issues
13
critical severity
vulnerability
2
license
11
11
high severity
vulnerability
6
license
2
meta
3
8
moderate severity
vulnerability
4
meta
4
3
low severity
vulnerability
1
license
2
4
licenses
49
MIT
11
N/A
1
Public Domain
1
BSD
Package created
14 Jul 2014
Version published
28 Jul 2015
Maintainers
3
Total deps
62
Direct deps
7
License
MIT

Issues

35

13 critical severity issues

critical
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@3.10.1 & others
Recommendation: Upgrade to version 3.3.3 or later
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io-client@1.7.4
Collapse
Expand

11 high severity issues

high
Recommendation: Upgrade to version 3.3.2 or later
via: socket.io-client@1.7.4
Recommendation: None
via: socket.io-client@1.7.4
Recommendation: Upgrade to version 2.6.9 or later
via: socket.io-client@1.7.4
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@3.10.1 & others
Recommendation: Upgrade to version 4.17.19 or later
via: lodash@3.10.1
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@3.10.1 & others
Recommendation: Validate that the package complies with your license policy
via: json-stable-stringify@1.1.1
Recommendation: Validate that the package complies with your license policy
via: node-rsa@0.2.30
via: socket.io-client@1.7.4
via: meshblu@1.30.1
via: url@0.10.3
Collapse
Expand

8 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@3.10.1 & others
Recommendation: Upgrade to version 2.6.9 or later
via: socket.io-client@1.7.4
Recommendation: Upgrade to version 2.0.0 or later
via: socket.io-client@1.7.4
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@3.10.1 & others
via: socket.io-client@1.7.4
via: socket.io-client@1.7.4
via: socket.io-client@1.7.4
via: socket.io-client@1.7.4
Collapse
Expand

3 low severity issues

low
Recommendation: Upgrade to version 4.17.5 or later
via: lodash@3.10.1 & others
Recommendation: Read and validate the license terms
via: json-stable-stringify@1.1.1
Recommendation: Read and validate the license terms
via: node-rsa@0.2.30
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
49 Packages, Including:
after@0.8.2
asn1@0.2.3
backo2@1.0.2
backo@1.1.0
base64-arraybuffer@0.1.5
call-bind@1.0.7
component-emitter@1.2.1
debug@2.2.0
debug@2.3.3
debug@2.6.9
define-data-property@1.1.4
engine.io-client@1.8.6
engine.io-parser@1.3.2
es-define-property@1.0.0
es-errors@1.3.0
function-bind@1.1.2
get-intrinsic@1.2.4
gopd@1.0.1
has-binary@0.1.7
has-cors@1.1.0
has-property-descriptors@1.0.2
has-proto@1.0.3
has-symbols@1.0.3
hasown@2.0.1
isarray@0.0.1
isarray@2.0.5
json-stable-stringify@1.1.1
json3@3.3.2
lodash@3.10.1
lodash@3.3.0
meshblu@1.30.1
ms@0.7.2
ms@2.0.0
object-keys@1.1.1
parsejson@0.0.3
parseqs@0.0.5
parseuri@0.0.5
punycode@1.3.2
querystring@0.2.0
set-function-length@1.2.1
socket.io-client@1.7.4
socket.io-parser@2.3.1
to-array@0.1.4
ultron@1.0.2
url@0.10.3
ws@1.1.5
wtf-8@1.0.0
xmlhttprequest-ssl@1.6.3
yeast@0.1.2

N/A

N/A
11 Packages, Including:
arraybuffer.slice@0.0.6
better-assert@1.0.2
blob@0.0.4
callsite@1.0.0
component-bind@1.0.0
component-emitter@1.1.2
component-inherit@0.0.3
indexof@0.0.1
ms@0.7.1
object-component@0.0.3
options@0.0.6

Public Domain

Invalid
Not OSI Approved
1 Packages, Including:
jsonify@0.0.1

BSD

Invalid
Not OSI Approved
1 Packages, Including:
node-rsa@0.2.30
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

7
All Dependencies CSV
β“˜ This is a list of meshblu 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
backo1.1.01.42 kBMIT
prod
debug2.6.916.13 kBMIT
prod
json-stable-stringify1.1.19.17 kBMIT
prod
1
1
lodash3.10.1169.48 kBMIT
prod
1
3
2
1
node-rsa0.2.3036.43 kBBSD
prod
1
3
2
2
socket.io-client1.7.4213.34 kBMIT
prod
12
4
6
url0.10.316.81 kBMIT
prod
1

Visualizations