Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 27, 2024 via pnpm

netlify-cms 2.10.192

An extensible, open source, Git-based, React CMS for static sites.
Package summary
Share
18
issues
4
critical severity
license
4
8
high severity
vulnerability
1
meta
7
3
moderate severity
meta
3
3
low severity
license
3
12
licenses
481
MIT
14
BSD-3-Clause
13
ISC
23
other licenses
BSD-2-Clause
8
N/A
4
Apache-2.0
3
WTFPL
2
+ 5 more
Package created
21 Sep 2016
Version published
13 Apr 2022
Maintainers
19
Total deps
531
Direct deps
7
License
MIT

Issues

18

4 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: netlify-cms-app@2.15.72
Recommendation: Check the package code and files for license information
via: netlify-cms-app@2.15.72
Recommendation: Check the package code and files for license information
via: netlify-cms-app@2.15.72 & others
Recommendation: Check the package code and files for license information
via: netlify-cms-app@2.15.72
Collapse
Expand

8 high severity issues

high
Recommendation: Upgrade to version 0.0.3 or later
via: netlify-cms-app@2.15.72
via: netlify-cms-app@2.15.72
via: create-react-class@15.7.0 & others
via: netlify-cms-app@2.15.72 & others
via: netlify-cms-app@2.15.72 & others
via: netlify-cms-app@2.15.72
via: netlify-cms-app@2.15.72
via: netlify-cms-app@2.15.72
Collapse
Expand

3 moderate severity issues

moderate
via: netlify-cms-app@2.15.72
via: netlify-cms-app@2.15.72
via: netlify-cms-app@2.15.72
Collapse
Expand

3 low severity issues

low
Recommendation: Read and validate the license terms
via: netlify-cms-app@2.15.72
Recommendation: Read and validate the license terms
via: netlify-cms-app@2.15.72
Recommendation: Read and validate the license terms
via: netlify-cms-app@2.15.72
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
481 Packages, Including:
@babel/code-frame@7.24.2
@babel/helper-module-imports@7.24.3
@babel/helper-string-parser@7.24.1
@babel/helper-validator-identifier@7.22.20
@babel/highlight@7.24.2
@babel/runtime@7.24.4
@babel/types@7.24.0
@emotion/babel-plugin@11.11.0
@emotion/cache@10.0.29
@emotion/cache@11.11.0
@emotion/core@10.3.1
@emotion/css@10.0.27
@emotion/hash@0.8.0
@emotion/hash@0.9.1
@emotion/is-prop-valid@0.8.8
@emotion/memoize@0.7.4
@emotion/memoize@0.8.1
@emotion/react@11.11.4
@emotion/serialize@0.11.16
@emotion/serialize@1.1.4
@emotion/sheet@0.9.4
@emotion/sheet@1.2.2
@emotion/styled-base@10.3.0
@emotion/styled@10.3.0
@emotion/stylis@0.8.5
@emotion/unitless@0.7.5
@emotion/unitless@0.8.1
@emotion/use-insertion-effect-with-fallbacks@1.0.1
@emotion/utils@0.11.3
@emotion/utils@1.2.1
@emotion/weak-memoize@0.2.5
@emotion/weak-memoize@0.3.1
@icons/material@0.2.4
@petamoriken/float16@3.8.6
@react-dnd/asap@4.0.1
@react-dnd/invariant@2.0.0
@react-dnd/shallowequal@2.0.0
@types/hast@2.3.10
@types/hoist-non-react-statics@3.3.5
@types/mdast@3.0.15
@types/node@20.12.7
@types/parse-json@4.0.2
@types/prop-types@15.7.12
@types/react-redux@7.1.33
@types/react@18.3.1
@types/unist@2.0.10
@types/unist@3.0.2
@types/vfile-message@2.0.0
@types/vfile@3.0.2
@types/zen-observable@0.8.7

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
14 Packages, Including:
exenv@1.2.2
hoist-non-react-statics@3.3.2
ieee754@1.2.1
js-base64@3.7.7
pbf@3.2.1
qs@6.12.1
react-transition-group@1.2.1
react-transition-group@4.4.5
redux-notifications@4.0.1
rw@1.3.3
source-map@0.5.7
source-map@0.7.4
sprintf-js@1.0.3
warning@3.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
13 Packages, Including:
@iarna/toml@2.2.5
@mapbox/mapbox-gl-style-spec@13.28.0
@mapbox/point-geometry@0.1.0
inherits@2.0.4
ini@2.0.0
lru-cache@6.0.0
material-colors@1.2.6
micro-api-client@3.3.0
minimatch@3.1.2
picocolors@1.0.0
quickselect@2.0.0
yallist@4.0.0
yaml@1.10.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
8 Packages, Including:
@mapbox/unitbezier@0.0.0
esprima@4.0.1
mapbox-to-css-font@2.4.4
node-polyglot@2.5.0
ol-mapbox-style@8.2.1
ol@6.15.1
uploadcare-widget@3.21.2
uri-js@4.4.1

N/A

N/A
4 Packages, Including:
@mapbox/jsonlint-lines-primitives@2.0.2
get-document@1.0.0
semaphore@1.1.0
trim@0.0.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
3 Packages, Including:
lerc@3.0.0
localforage@1.10.0
web-worker@1.3.0

Do What The F*ck You Want To Public License

Permissive
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
sublicense
distribute
modify
Cannot
Must
rename
2 Packages, Including:
truncate-utf8-bytes@1.0.2
utf8-byte-length@1.0.4

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

(MPL-2.0 OR Apache-2.0)

Permissive
1 Packages, Including:
dompurify@2.5.1

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@2.1.0

WTFPL OR ISC

Permissive
1 Packages, Including:
sanitize-filename@1.6.3

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
xml-utils@1.8.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

7
All Dependencies CSV
β“˜ This is a list of netlify-cms 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
codemirror5.65.16738.64 kBMIT
prod peer
create-react-class15.7.020.58 kBMIT
prod
1
netlify-cms-app2.15.725.71 MBMIT
prod
4
8
3
3
netlify-cms-media-library-cloudinary1.3.1031.48 kBMIT
prod
1
netlify-cms-media-library-uploadcare0.5.10560.81 kBMIT
prod
react-dom16.14.0722.53 kBMIT
prod peer
2
react16.14.059.16 kBMIT
prod peer
1

Visualizations