Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 2, 2024 via pnpm
Package summary
Share
8
issues
5
high severity
license
2
meta
3
1
moderate severity
vulnerability
1
2
low severity
license
2
8
licenses
137
MIT
87
Apache-2.0
15
ISC
18
other licenses
BSD-3-Clause
13
0BSD
2
New Relic Pre-Release
1
Python-2.0
1
+ 1 more
Package created
10 Oct 2012
Version published
7 Sep 2023
Maintainers
1
Total deps
257
Direct deps
19
License
Apache-2.0

Issues

8

5 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: @newrelic/security-agent@0.2.1
Recommendation: Validate that the package complies with your license policy
via: @newrelic/security-agent@0.2.1
via: @contrast/fn-inspect@3.4.0
via: @newrelic/native-metrics@10.1.0
via: @grpc/grpc-js@1.10.5 & others
Collapse
Expand

1 moderate severity issue

moderate
Recommendation: Upgrade to version 0.28.0 or later
via: @newrelic/security-agent@0.2.1
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: @newrelic/security-agent@0.2.1
Recommendation: Read and validate the license terms
via: @newrelic/security-agent@0.2.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
137 Packages, Including:
@colors/colors@1.6.0
@contrast/fn-inspect@3.4.0
@js-sdsl/ordered-map@4.4.2
@types/concat-stream@1.6.1
@types/form-data@0.0.33
@types/node@10.17.60
@types/node@20.12.2
@types/node@8.10.66
@types/qs@6.9.14
@types/triple-beam@1.3.5
@tyriar/fibonacci-heap@2.0.9
acorn-import-assertions@1.9.0
acorn@8.11.3
agent-base@7.1.1
ansi-regex@5.0.1
ansi-styles@4.3.0
asap@2.0.6
asynckit@0.4.0
axios@0.21.4
base64-js@1.5.1
bignumber.js@9.1.2
bl@4.1.0
bowser@2.11.0
buffer-from@1.1.2
buffer@5.7.1
call-bind@1.0.7
check-disk-space@3.3.1
cjs-module-lexer@1.2.3
color-convert@2.0.1
color-name@1.1.4
combined-stream@1.0.8
concat-stream@1.6.2
concat-stream@2.0.0
content-type@1.0.5
core-util-is@1.0.3
date-format@4.0.14
debug@4.3.4
define-data-property@1.1.4
delayed-stream@1.0.0
emoji-regex@8.0.0
end-of-stream@1.4.4
es-define-property@1.0.0
es-errors@1.3.0
escalade@3.1.2
execspawn@1.0.1
extend-shallow@2.0.1
fast-safe-stringify@2.1.1
fast-xml-parser@4.2.5
fecha@4.2.3
find-package-json@1.2.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
87 Packages, Including:
@aws-crypto/crc32@3.0.0
@aws-crypto/ie11-detection@3.0.0
@aws-crypto/sha256-browser@3.0.0
@aws-crypto/sha256-js@3.0.0
@aws-crypto/supports-web-crypto@3.0.0
@aws-crypto/util@3.0.0
@aws-sdk/client-lambda@3.540.0
@aws-sdk/client-sso-oidc@3.540.0
@aws-sdk/client-sso@3.540.0
@aws-sdk/client-sts@3.540.0
@aws-sdk/core@3.535.0
@aws-sdk/credential-provider-env@3.535.0
@aws-sdk/credential-provider-http@3.535.0
@aws-sdk/credential-provider-ini@3.540.0
@aws-sdk/credential-provider-node@3.540.0
@aws-sdk/credential-provider-process@3.535.0
@aws-sdk/credential-provider-sso@3.540.0
@aws-sdk/credential-provider-web-identity@3.540.0
@aws-sdk/middleware-host-header@3.535.0
@aws-sdk/middleware-logger@3.535.0
@aws-sdk/middleware-recursion-detection@3.535.0
@aws-sdk/middleware-user-agent@3.540.0
@aws-sdk/region-config-resolver@3.535.0
@aws-sdk/token-providers@3.540.0
@aws-sdk/types@3.535.0
@aws-sdk/util-endpoints@3.540.0
@aws-sdk/util-locate-window@3.535.0
@aws-sdk/util-user-agent-browser@3.535.0
@aws-sdk/util-user-agent-node@3.535.0
@aws-sdk/util-utf8-browser@3.259.0
@grpc/grpc-js@1.10.5
@grpc/proto-loader@0.7.12
@newrelic/aws-sdk@7.3.0
@newrelic/koa@8.0.1
@newrelic/native-metrics@10.1.0
@newrelic/superagent@7.0.1
@prisma/prisma-fmt-wasm@4.17.0-16.27eb2449f178cd9fe1a4b892d732cc4795f75085
@smithy/abort-controller@2.2.0
@smithy/config-resolver@2.2.0
@smithy/core@1.4.1
@smithy/credential-provider-imds@2.3.0
@smithy/eventstream-codec@2.2.0
@smithy/eventstream-serde-browser@2.2.0
@smithy/eventstream-serde-config-resolver@2.2.0
@smithy/eventstream-serde-node@2.2.0
@smithy/eventstream-serde-universal@2.2.0
@smithy/fetch-http-handler@2.5.0
@smithy/hash-node@2.2.0
@smithy/invalid-dependency@2.2.0
@smithy/is-array-buffer@2.2.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
15 Packages, Including:
chownr@1.1.4
cliui@8.0.1
flatted@3.3.1
get-caller-file@2.0.5
graceful-fs@4.2.11
inherits@2.0.4
json-stringify-safe@5.0.1
lru-cache@6.0.0
minimalistic-assert@1.0.1
once@1.4.0
semver@7.6.0
wrappy@1.0.2
y18n@5.0.8
yallist@4.0.0
yargs-parser@21.1.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
13 Packages, Including:
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
ieee754@1.2.1
protobufjs@7.2.6
qs@6.12.0

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

New Relic Pre-Release

Invalid
Not OSI Approved
1 Packages, Including:
@newrelic/security-agent@0.2.1

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

BSD

Invalid
Not OSI Approved
1 Packages, Including:
parse-cache-control@1.0.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

19
All Dependencies CSV
β“˜ This is a list of newrelic 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@contrast/fn-inspect3.4.0549.32 kBMIT
prod optional
1
@grpc/grpc-js1.10.51.76 MBApache-2.0
prod
1
@grpc/proto-loader0.7.12114.79 kBApache-2.0
prod
1
@newrelic/aws-sdk7.3.0197.27 kBApache-2.0
prod
@newrelic/koa8.0.144.7 kBApache-2.0
prod
@newrelic/native-metrics10.1.01.73 MBApache-2.0
prod optional
1
@newrelic/security-agent0.2.190.04 kBNew Relic Pre-Release
prod
2
1
2
@newrelic/superagent7.0.140.7 kBApache-2.0
prod
@prisma/prisma-fmt-wasm4.17.0-16.27eb2449f178cd9fe1a4b892d732cc4795f75085822.35 kBApache-2.0
prod optional
@tyriar/fibonacci-heap2.0.98.53 kBMIT
prod
concat-stream2.0.03.7 kBMIT
prod
https-proxy-agent7.0.434.43 kBMIT
prod
import-in-the-middle1.7.318.97 kBApache-2.0
prod
json-bigint1.0.010.97 kBMIT
prod
json-stringify-safe5.0.13.92 kBISC
prod
readable-stream3.6.232.46 kBMIT
prod optional
require-in-the-middle7.3.016.48 kBMIT
prod
semver7.6.026.57 kBISC
prod optional
winston-transport4.7.011.56 kBMIT
prod

Visualizations