Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 21, 2024 via pnpm

mqtt2opcua 0.0.15

Bi-directional MQTT OPCUA bridge
Package summary
Share
21
issues
6
critical severity
license
6
3
high severity
vulnerability
2
license
1
10
moderate severity
meta
10
2
low severity
vulnerability
1
license
1
9
licenses
233
MIT
22
ISC
6
N/A
9
other licenses
BSD-3-Clause
2
Apache-2.0
2
0BSD
2
BlueOak-1.0.0
1
+ 2 more
Package created
22 Jul 2015
Version published
27 Nov 2016
Maintainers
1
Total deps
270
Direct deps
3
License
MIT

Issues

21

6 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: node-opcua@2.120.0
Recommendation: Check the package code and files for license information
via: node-opcua@2.120.0
Recommendation: Check the package code and files for license information
via: node-opcua@2.120.0
Recommendation: Check the package code and files for license information
via: mqtt@1.1.5
Recommendation: Check the package code and files for license information
via: mqtt@1.1.5
Recommendation: Check the package code and files for license information
via: node-opcua@2.120.0
Collapse
Expand

3 high severity issues

high
Recommendation: Upgrade to version 1.1.1 or later
via: mqtt@1.1.5
Recommendation: Upgrade to version 1.1.5 or later
via: mqtt@1.1.5
Recommendation: Read and validate the license terms
via: node-opcua@2.120.0
Collapse
Expand

10 moderate severity issues

moderate
via: node-opcua@2.120.0
via: node-opcua@2.120.0
via: node-opcua@2.120.0
via: node-opcua@2.120.0
via: node-opcua@2.120.0
via: node-opcua@2.120.0
via: node-opcua@2.120.0
via: node-opcua@2.120.0
via: node-opcua@2.120.0
via: node-opcua@2.120.0
Collapse
Expand

2 low severity issues

low
Recommendation: Upgrade to version 1.0.1 or later
via: mqtt@1.1.5
Recommendation: Read and validate the license terms
via: node-opcua@2.120.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
233 Packages, Including:
@leichtgewicht/ip-codec@2.0.4
@peculiar/asn1-cms@2.3.8
@peculiar/asn1-csr@2.3.8
@peculiar/asn1-ecc@2.3.8
@peculiar/asn1-pfx@2.3.8
@peculiar/asn1-pkcs8@2.3.8
@peculiar/asn1-pkcs9@2.3.8
@peculiar/asn1-rsa@2.3.8
@peculiar/asn1-schema@2.3.8
@peculiar/asn1-x509-attr@2.3.8
@peculiar/asn1-x509@2.3.8
@peculiar/json-schema@1.1.12
@peculiar/webcrypto@1.4.5
@peculiar/x509@1.9.7
@ster5/global-mutex@2.0.0
@types/asn1@0.2.4
@types/async@3.2.24
@types/dns-packet@5.6.5
@types/jsrsasign@10.5.12
@types/lodash@4.14.202
@types/mkdirp@1.0.2
@types/multicast-dns@7.2.4
@types/node@20.11.19
@types/proper-lockfile@4.1.4
@types/retry@0.12.5
@types/semver@7.5.7
@types/sshpk@1.17.4
ansi-regex@5.0.1
ansi-styles@4.3.0
any-promise@1.3.0
array-flatten@2.1.2
asn1@0.2.6
assert-plus@1.0.0
assert@2.1.0
async@3.2.5
available-typed-arrays@1.0.7
backoff@2.5.0
balanced-match@1.0.2
binary-extensions@2.2.0
bindings@1.2.1
bl@1.2.3
brace-expansion@2.0.1
braces@3.0.2
buffer-crc32@0.2.13
buffer-from@1.1.2
bufferutil@1.1.0
byline@5.0.0
call-bind@1.0.7
chalk@4.1.2
chokidar@3.6.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
22 Packages, Including:
anymatch@3.1.3
cliui@8.0.1
fs.realpath@1.0.0
get-caller-file@2.0.5
glob-parent@5.1.2
glob@9.3.5
graceful-fs@4.2.11
inherits@2.0.4
lru-cache@10.2.0
lru-cache@6.0.0
minimatch@8.0.4
minipass@4.2.8
minipass@7.0.4
once@1.4.0
reduplexer@1.1.0
rimraf@4.4.1
semver@7.6.0
signal-exit@3.0.7
wrappy@1.0.2
y18n@5.0.8
yallist@4.0.0
yargs-parser@21.1.1

N/A

N/A
6 Packages, Including:
cli-table@0.3.11
dequeue@1.0.5
humanize@0.0.9
mqtt@1.1.5
options@0.0.6
precond@0.2.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
asn1js@3.0.5
bcrypt-pbkdf@1.0.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
long@4.0.0
reflect-metadata@0.2.1

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

Blue Oak Model License 1.0.0

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
path-scurry@1.10.1

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
websocket-stream@1.5.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

3
All Dependencies CSV
β“˜ This is a list of mqtt2opcua 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
mqtt1.1.5114.22 kBUNKNOWN
prod
2
2
1
node-opcua2.120.07.07 kBMIT
prod
4
1
10
1
qlobber8.0.113.21 kBMIT
prod

Visualizations