Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 5, 2024 via pnpm

openpgp 5.10.1

OpenPGP.js is a Javascript implementation of the OpenPGP protocol. This is defined in RFC 4880.
Package summary
Share
2
issues
1
moderate severity
license
1
1
low severity
license
1
3
licenses
3
MIT
2
ISC
1
LGPL-3.0+
Package created
12 Jan 2014
Version published
29 Aug 2023
Maintainers
5
Total deps
6
Direct deps
1
License
LGPL-3.0+

Issues

2

1 moderate severity issue

moderate
Recommendation: Validate that the package complies with your license policy
via: openpgp@5.10.1
Collapse
Expand

1 low severity issue

low
via: openpgp@5.10.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
asn1.js@5.4.1
bn.js@4.12.0
safer-buffer@2.1.2

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
inherits@2.0.4
minimalistic-assert@1.0.1

GNU Lesser General Public License v3.0 or later

Weakly Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
use-patent-claims
Cannot
sublicense
hold-liable
Must
include-original
state-changes
disclose-source
include-license
include-copyright
include-install-instructions
1 Packages, Including:
openpgp@5.10.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

1
All Dependencies CSV
β“˜ This is a list of openpgp 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
asn1.js5.4.113.23 kBMIT
prod

Visualizations