Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 8, 2024 via pnpm
Package summary
Share
12
issues
7
high severity
license
4
meta
3
1
moderate severity
meta
1
4
low severity
license
4
10
licenses
174
MIT
88
Apache-2.0
46
ISC
22
other licenses
BSD-3-Clause
14
BlueOak-1.0.0
2
0BSD
2
New Relic Pre-Release
1
+ 3 more
Package created
10 Oct 2012
Version published
14 Dec 2023
Maintainers
1
Total deps
330
Direct deps
20
License
Apache-2.0

Issues

12

7 high severity issues

high
Recommendation: Read and validate the license terms
via: @newrelic/native-metrics@10.1.1
Recommendation: Read and validate the license terms
via: @newrelic/native-metrics@10.1.1
Recommendation: Validate that the package complies with your license policy
via: @newrelic/security-agent@0.5.0
Recommendation: Validate that the package complies with your license policy
via: @newrelic/security-agent@0.5.0
via: @contrast/fn-inspect@3.4.0
via: @newrelic/native-metrics@10.1.1
via: @grpc/grpc-js@1.10.7 & others
Collapse
Expand

1 moderate severity issue

moderate
via: @newrelic/native-metrics@10.1.1
Collapse
Expand

4 low severity issues

low
Recommendation: Read and validate the license terms
via: @newrelic/native-metrics@10.1.1
Recommendation: Read and validate the license terms
via: @newrelic/native-metrics@10.1.1
Recommendation: Read and validate the license terms
via: @newrelic/security-agent@0.5.0
Recommendation: Read and validate the license terms
via: @newrelic/security-agent@0.5.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
174 Packages, Including:
@colors/colors@1.6.0
@contrast/fn-inspect@3.4.0
@js-sdsl/ordered-map@4.4.2
@pkgjs/parseargs@0.11.0
@types/concat-stream@1.6.1
@types/form-data@0.0.33
@types/node@10.17.60
@types/node@20.12.10
@types/node@8.10.66
@types/qs@6.9.15
@types/triple-beam@1.3.5
@tyriar/fibonacci-heap@2.0.9
acorn-import-attributes@1.9.5
acorn@8.11.3
agent-base@7.1.1
aggregate-error@3.1.0
ansi-regex@5.0.1
ansi-regex@6.0.1
ansi-styles@4.3.0
ansi-styles@6.2.1
asap@2.0.6
asynckit@0.4.0
axios@1.6.0
balanced-match@1.0.2
base64-js@1.5.1
bignumber.js@9.1.2
bl@4.1.0
bowser@2.11.0
brace-expansion@2.0.1
buffer-from@1.1.2
buffer@5.7.1
call-bind@1.0.7
check-disk-space@3.4.0
cjs-module-lexer@1.3.1
clean-stack@2.2.0
color-convert@2.0.1
color-name@1.1.4
combined-stream@1.0.8
concat-stream@1.6.2
concat-stream@2.0.0
content-type@1.0.5
core-util-is@1.0.3
cross-spawn@7.0.3
date-format@4.0.14
debug@4.3.4
define-data-property@1.1.4
delayed-stream@1.0.0
eastasianwidth@0.2.0
emoji-regex@8.0.0
emoji-regex@9.2.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
88 Packages, Including:
@aws-crypto/crc32@3.0.0
@aws-crypto/ie11-detection@3.0.0
@aws-crypto/sha256-browser@3.0.0
@aws-crypto/sha256-js@3.0.0
@aws-crypto/supports-web-crypto@3.0.0
@aws-crypto/util@3.0.0
@aws-sdk/client-lambda@3.569.0
@aws-sdk/client-sso-oidc@3.569.0
@aws-sdk/client-sso@3.568.0
@aws-sdk/client-sts@3.569.0
@aws-sdk/core@3.567.0
@aws-sdk/credential-provider-env@3.568.0
@aws-sdk/credential-provider-http@3.568.0
@aws-sdk/credential-provider-ini@3.568.0
@aws-sdk/credential-provider-node@3.569.0
@aws-sdk/credential-provider-process@3.568.0
@aws-sdk/credential-provider-sso@3.568.0
@aws-sdk/credential-provider-web-identity@3.568.0
@aws-sdk/middleware-host-header@3.567.0
@aws-sdk/middleware-logger@3.568.0
@aws-sdk/middleware-recursion-detection@3.567.0
@aws-sdk/middleware-user-agent@3.567.0
@aws-sdk/region-config-resolver@3.567.0
@aws-sdk/token-providers@3.568.0
@aws-sdk/types@3.567.0
@aws-sdk/util-endpoints@3.567.0
@aws-sdk/util-locate-window@3.568.0
@aws-sdk/util-user-agent-browser@3.567.0
@aws-sdk/util-user-agent-node@3.568.0
@aws-sdk/util-utf8-browser@3.259.0
@grpc/grpc-js@1.10.7
@grpc/proto-loader@0.7.13
@newrelic/aws-sdk@7.4.1
@newrelic/koa@8.0.1
@newrelic/native-metrics@10.1.1
@newrelic/superagent@7.0.1
@prisma/prisma-fmt-wasm@4.17.0-16.27eb2449f178cd9fe1a4b892d732cc4795f75085
@smithy/abort-controller@2.2.0
@smithy/config-resolver@2.2.0
@smithy/core@1.4.2
@smithy/credential-provider-imds@2.3.0
@smithy/eventstream-codec@2.2.0
@smithy/eventstream-serde-browser@2.2.0
@smithy/eventstream-serde-config-resolver@2.2.0
@smithy/eventstream-serde-node@2.2.0
@smithy/eventstream-serde-universal@2.2.0
@smithy/fetch-http-handler@2.5.0
@smithy/hash-node@2.2.0
@smithy/invalid-dependency@2.2.0
@smithy/is-array-buffer@2.2.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
46 Packages, Including:
@isaacs/cliui@8.0.2
@npmcli/agent@2.2.2
@npmcli/fs@3.1.1
abbrev@2.0.0
cacache@18.0.3
chownr@1.1.4
chownr@2.0.0
cliui@8.0.1
flatted@3.3.1
foreground-child@3.1.1
fs-minipass@2.1.0
fs-minipass@3.0.3
get-caller-file@2.0.5
glob@10.3.12
graceful-fs@4.2.11
inherits@2.0.4
isexe@2.0.0
isexe@3.1.1
json-stringify-safe@5.0.1
lru-cache@10.2.2
make-fetch-happen@13.0.1
minimalistic-assert@1.0.1
minimatch@9.0.4
minipass-collect@2.0.1
minipass-flush@1.0.5
minipass-pipeline@1.2.4
minipass-sized@1.0.3
minipass@3.3.6
minipass@5.0.0
minipass@7.1.0
nopt@7.2.1
once@1.4.0
proc-log@3.0.0
proc-log@4.2.0
semver@7.6.1
signal-exit@4.1.0
ssri@10.0.6
tar@6.2.1
unique-filename@3.0.0
unique-slug@4.0.0
which@2.0.2
which@4.0.0
wrappy@1.0.2
y18n@5.0.8
yallist@4.0.0
yargs-parser@21.1.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
14 Packages, Including:
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
ieee754@1.2.1
protobufjs@7.2.6
qs@6.12.1
sprintf-js@1.1.3

Blue Oak Model License 1.0.0

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
jackspeak@2.3.6
path-scurry@1.10.2

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

New Relic Pre-Release

Invalid
Not OSI Approved
1 Packages, Including:
@newrelic/security-agent@0.5.0

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
http-cache-semantics@4.1.1

BSD

Invalid
Not OSI Approved
1 Packages, Including:
parse-cache-control@1.0.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

20
All Dependencies CSV
β“˜ This is a list of newrelic 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@contrast/fn-inspect3.4.0549.32 kBMIT
prod optional
1
@grpc/grpc-js1.10.71.76 MBApache-2.0
prod
1
@grpc/proto-loader0.7.13117.19 kBApache-2.0
prod
1
@newrelic/aws-sdk7.4.1198.04 kBApache-2.0
prod
@newrelic/koa8.0.144.7 kBApache-2.0
prod
@newrelic/native-metrics10.1.11.73 MBApache-2.0
prod optional
3
1
2
@newrelic/security-agent0.5.092.47 kBNew Relic Pre-Release
prod
2
2
@newrelic/superagent7.0.140.7 kBApache-2.0
prod
@prisma/prisma-fmt-wasm4.17.0-16.27eb2449f178cd9fe1a4b892d732cc4795f75085822.35 kBApache-2.0
prod optional
@tyriar/fibonacci-heap2.0.98.53 kBMIT
prod
concat-stream2.0.03.7 kBMIT
prod
https-proxy-agent7.0.434.43 kBMIT
prod optional
import-in-the-middle1.7.468.55 kBApache-2.0
prod
json-bigint1.0.010.97 kBMIT
prod
json-stringify-safe5.0.13.92 kBISC
prod
module-details-from-path1.0.32.14 kBMIT
prod
readable-stream3.6.232.46 kBMIT
prod optional
require-in-the-middle7.3.016.48 kBMIT
prod
semver7.6.193.27 kBISC
prod optional
winston-transport4.7.011.56 kBMIT
prod

Visualizations