Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 2, 2024 via pnpm

next-auth 4.23.1

Authentication for Next.js
Package summary
Share
5
issues
1
high severity
license
1
3
moderate severity
vulnerability
2
meta
1
1
low severity
license
1
7
licenses
36
MIT
5
ISC
1
Apache-2.0
4
other licenses
CC-BY-4.0
1
BSD-2-Clause
1
BSD-3-Clause
1
0BSD
1
Package created
22 Jan 2018
Version published
16 Aug 2023
Maintainers
3
Total deps
46
Direct deps
12
License
ISC

Issues

5

1 high severity issue

high
Recommendation: Read and validate the license terms
via: next@13.5.6
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Upgrade to version 4.24.5 or later
via: next-auth@4.23.1
Recommendation: Upgrade to version 4.24.5 or later
via: next-auth@4.23.1
via: next@13.5.6
Collapse
Expand

1 low severity issue

low
Recommendation: Read and validate the license terms
via: next@13.5.6
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
36 Packages, Including:
@babel/runtime@7.24.1
@next/env@13.5.6
@next/swc-darwin-arm64@13.5.6
@next/swc-darwin-x64@13.5.6
@next/swc-linux-arm64-gnu@13.5.6
@next/swc-linux-arm64-musl@13.5.6
@next/swc-linux-x64-gnu@13.5.6
@next/swc-linux-x64-musl@13.5.6
@next/swc-win32-arm64-msvc@13.5.6
@next/swc-win32-ia32-msvc@13.5.6
@next/swc-win32-x64-msvc@13.5.6
@panva/hkdf@1.1.1
busboy@1.6.0
client-only@0.0.1
cookie@0.5.0
jose@4.15.5
js-tokens@4.0.0
loose-envify@1.4.0
nanoid@3.3.7
next@13.5.6
oauth@0.9.15
object-hash@2.2.0
oidc-token-hash@5.0.3
openid-client@5.6.5
postcss@8.4.31
preact-render-to-string@5.2.6
preact@10.20.1
pretty-format@3.8.0
react-dom@18.2.0
react@18.2.0
regenerator-runtime@0.14.1
scheduler@0.23.0
streamsearch@1.1.0
styled-jsx@5.1.1
uuid@8.3.2
watchpack@2.4.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
graceful-fs@4.2.11
lru-cache@6.0.0
next-auth@4.23.1
picocolors@1.0.0
yallist@4.0.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
1 Packages, Including:
@swc/helpers@0.5.2

Creative Commons Attribution 4.0 International

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
caniuse-lite@1.0.30001605

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
glob-to-regexp@0.4.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
source-map-js@1.2.0

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
1 Packages, Including:
tslib@2.6.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

12
All Dependencies CSV
β“˜ This is a list of next-auth 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@babel/runtime7.24.1256 kBMIT
prod
@panva/hkdf1.1.13.66 kBMIT
prod
cookie0.5.07.87 kBMIT
prod
jose4.15.5535.58 kBMIT
prod
next13.5.616.71 MBMIT
prod peer
1
1
1
oauth0.9.1526.89 kBMIT
prod
openid-client5.6.5131.54 kBMIT
prod
preact-render-to-string5.2.6101.86 kBMIT
prod
preact10.20.11.31 MBMIT
prod peer
react-dom18.2.01.04 MBMIT
prod peer
react18.2.079.25 kBMIT
prod peer
uuid8.3.227.32 kBMIT
prod

Visualizations