Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 3, 2024 via pnpm

pastash 1.0.47

Spaghetti I/O Processing, Interpolation, Correlation and beyond - nodejs logstash + beat
Package summary
Share
69
issues
12
critical severity
vulnerability
3
license
9
37
high severity
vulnerability
10
license
12
meta
15
10
moderate severity
vulnerability
8
meta
2
10
low severity
license
10
18
licenses
288
MIT
38
ISC
19
Apache-2.0
44
other licenses
BSD-2-Clause
10
BSD-3-Clause
9
N/A
9
MIT/X11
3
+ 11 more
Package created
9 Sep 2017
Version published
17 Dec 2019
Maintainers
1
Total deps
389
Direct deps
39
License
Apache-2.0

Issues

69

12 critical severity issues

critical
Recommendation: Upgrade to version 1.1.0 or later
via: @pm2/io@2.4.7
Recommendation: Upgrade to version 1.12.1 or later
via: kafka-node@2.2.3
Recommendation: Upgrade to version 0.2.4 or later
via: mkdirp@0.5.1 & others
Recommendation: Check the package code and files for license information
via: amqplib@0.5.1
Recommendation: Check the package code and files for license information
via: amqplib@0.5.1
Recommendation: Check the package code and files for license information
via: geoip-lite@1.2.1 & others
Recommendation: Check the package code and files for license information
via: node-netflowv9@0.2.16
Recommendation: Check the package code and files for license information
via: metrics-influxdb@1.0.0
Recommendation: Check the package code and files for license information
via: modesl@1.2.1
Recommendation: Check the package code and files for license information
via: msgpack@1.0.3
Recommendation: Check the package code and files for license information
via: nsqjs@0.10.1
Recommendation: Check the package code and files for license information
via: kafka-node@2.2.3
Collapse
Expand

37 high severity issues

high
Recommendation: Upgrade to version 0.2019.416 or later
via: gun@0.9.7
Recommendation: Upgrade to version 3.1.1 or later
via: redis@2.8.0
Recommendation: Upgrade to version 2.814.0 or later
via: aws-sdk@2.112.0
Recommendation: Upgrade to version 5.0.0 or later
via: @pm2/io@2.4.7
Recommendation: Upgrade to version 3.0.1 or later
via: @pm2/io@2.4.7
Recommendation: Upgrade to version 1.0.12 or later
via: geoip-lite@1.2.1
Recommendation: Upgrade to version 2.29.4 or later
via: moment@2.19.3
Recommendation: Upgrade to version 2.29.2 or later
via: moment@2.19.3
Recommendation: None
via: hoek@5.0.4
Recommendation: Upgrade to version 2.6.4 or later
via: async@2.6.0 & others
Recommendation: Validate that the package complies with your license policy
via: geoip-lite@1.2.1 & others
Recommendation: Validate that the package complies with your license policy
via: optimist@0.6.1
Recommendation: Validate that the package complies with your license policy
via: geoip-lite@1.2.1 & others
Recommendation: Validate that the package complies with your license policy
via: hep-js@1.0.20
Recommendation: Validate that the package complies with your license policy
via: node-netflowv9@0.2.16
Recommendation: Validate that the package complies with your license policy
via: node-sflow@0.0.6
Recommendation: Validate that the package complies with your license policy
via: geoip-lite@1.2.1
Recommendation: Validate that the license expression complies with your license policy
via: gun@0.9.7
Recommendation: Validate that the package complies with your license policy
via: aws-sdk@2.112.0
Recommendation: Validate that the package complies with your license policy
via: log4node@0.1.6
Recommendation: Validate that the license expression complies with your license policy
via: kafka-node@2.2.3 & others
Recommendation: Validate that the package complies with your license policy
via: tinymath@0.1.11
via: gun@0.9.7
via: nsqjs@0.10.1
via: aws-sdk@2.112.0
via: nsqjs@0.10.1 & others
via: hoek@5.0.4
via: json2csv@4.5.4
via: mkdirp@0.5.1 & others
via: geoip-lite@1.2.1
via: aws-sdk@2.112.0 & others
via: nsqjs@0.10.1 & others
via: kafka-node@2.2.3 & others
via: sqlite3@3.1.13
via: tinymath@0.1.11
via: aws-sdk@2.112.0
via: @pm2/io@2.4.7 & others
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 2.0.1 or later
via: @pm2/io@2.4.7
Recommendation: Upgrade to version 2.2.3 or later
via: https-proxy-agent@2.2.0
Recommendation: Upgrade to version 0.2.1 or later
via: mkdirp@0.5.1 & others
Recommendation: Upgrade to version 5.7.2 or later
via: @pm2/io@2.4.7
Recommendation: Upgrade to version 1.1.9 or later
via: @pm2/io@2.4.7
Recommendation: Upgrade to version 4.1.3 or later
via: nsqjs@0.10.1 & others
Recommendation: Upgrade to version 0.5.0 or later
via: aws-sdk@2.112.0 & others
Recommendation: None
via: nsqjs@0.10.1 & others
via: @pm2/io@2.4.7
via: @pm2/io@2.4.7
Collapse
Expand

10 low severity issues

low
Recommendation: Read and validate the license terms
via: geoip-lite@1.2.1 & others
Recommendation: Read and validate the license terms
via: optimist@0.6.1
Recommendation: Read and validate the license terms
via: geoip-lite@1.2.1 & others
Recommendation: Read and validate the license terms
via: hep-js@1.0.20
Recommendation: Read and validate the license terms
via: node-netflowv9@0.2.16
Recommendation: Read and validate the license terms
via: node-sflow@0.0.6
Recommendation: Read and validate the license terms
via: geoip-lite@1.2.1
Recommendation: Read and validate the license terms
via: aws-sdk@2.112.0
Recommendation: Read and validate the license terms
via: log4node@0.1.6
Recommendation: Read and validate the license terms
via: tinymath@0.1.11
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
288 Packages, Including:
@babel/runtime@7.24.5
@pm2/io@2.4.7
@qxip/bencode@1.0.0
@types/node@20.12.8
@types/readable-stream@4.0.12
@types/ws@8.5.10
abort-controller@3.0.0
agent-base@4.2.1
agent-base@4.3.0
ajv@6.12.6
amqplib@0.5.1
ansi-regex@2.1.1
asn1@0.2.6
assert-plus@1.0.0
ast-types@0.14.2
async-limiter@1.0.1
async@0.2.10
async@2.6.0
async@2.6.4
async@3.2.5
asynckit@0.4.0
available-typed-arrays@1.0.7
aws4@1.12.0
balanced-match@1.0.2
base64-js@1.5.1
bignumber.js@6.0.0
binary-parser@1.9.2
binary@0.3.0
bindings@1.2.1
bindings@1.5.0
bl@1.2.3
bl@6.0.12
bluebird@3.7.2
brace-expansion@1.1.11
buffer-alloc-unsafe@1.1.0
buffer-alloc@1.2.0
buffer-crc32@0.2.13
buffer-fill@1.0.0
buffer-from@1.1.2
buffer@4.9.1
buffer@4.9.2
buffer@6.0.3
buffermaker@1.2.1
bytes@3.1.2
call-bind@1.0.7
clone@1.0.4
co@4.6.0
code-point-at@1.1.0
colors@1.4.0
combined-stream@1.0.8

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
38 Packages, Including:
@pm2/agent-node@1.1.10
aproba@1.2.0
are-we-there-yet@1.1.7
chownr@1.1.4
console-control-strings@1.1.0
fs.realpath@1.0.0
gauge@2.7.4
glob@7.2.3
graceful-fs@3.0.12
har-schema@2.0.0
has-unicode@2.0.1
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
json-stringify-safe@5.0.1
lru-cache@10.2.2
lru-cache@4.1.5
lru-cache@5.1.1
minimatch@3.1.2
natives@1.1.6
npmlog@4.1.2
once@1.4.0
pseudomap@1.0.2
rimraf@2.7.1
sax@1.2.1
sax@1.3.0
semver@5.5.0
semver@5.7.2
set-blocking@2.0.0
setprototypeof@1.2.0
signal-exit@3.0.2
signal-exit@3.0.7
split2@2.2.0
split2@4.2.0
wide-align@1.1.5
wrappy@1.0.2
yallist@2.1.2
yallist@3.1.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
19 Packages, Including:
aws-sdk@2.112.0
aws-sdk@2.1613.0
aws-sign2@0.7.0
b4a@1.6.6
caseless@0.12.0
deep-metrics@0.0.2
detect-libc@1.0.3
fast-text-encoding@1.0.6
forever-agent@0.6.1
geoip-lite@1.2.1
jmespath@0.16.0
long@1.1.2
oauth-sign@0.9.0
pastash@1.0.47
request@2.88.2
splunk-logging@0.9.3
tslib@1.9.3
tunnel-agent@0.6.0
vxx@1.2.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
10 Packages, Including:
async-listener@0.6.10
continuation-local-storage@3.2.1
emitter-listener@1.1.2
escodegen@1.14.3
esprima@3.1.3
esprima@4.0.1
estraverse@4.3.0
esutils@2.0.3
shimmer@1.2.1
uri-js@4.4.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
bcrypt-pbkdf@1.0.2
hoek@5.0.4
ieee754@1.1.13
ieee754@1.2.1
ndjson@1.5.0
qs@6.5.3
source-map@0.6.1
sqlite3@3.1.13
tough-cookie@2.5.0

N/A

N/A
9 Packages, Including:
bitsyntax@0.0.4
buffer-more-ints@0.0.2
buffers@0.1.1
dequeue@1.0.5
metrics@0.1.21
modesl@1.2.1
msgpack@1.0.3
node-state@1.4.4
underscore@1.4.4

MIT/X11

Invalid
Not OSI Approved
3 Packages, Including:
chainsaw@0.1.0
optimist@0.6.1
traverse@0.3.9

GPLv2

Invalid
Not OSI Approved
3 Packages, Including:
hep-js@1.0.20
node-netflowv9@0.2.16
node-sflow@0.0.6

(MIT OR WTFPL)

Permissive
1 Packages, Including:
expand-template@2.0.3

BSD

Invalid
Not OSI Approved
1 Packages, Including:
fstream@0.1.31

(Zlib OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
gun@0.9.7

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
jmespath@0.15.0

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

Apache2

Invalid
Not OSI Approved
1 Packages, Including:
log4node@0.1.6

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

Apache 2

Invalid
Not OSI Approved
1 Packages, Including:
tinymath@0.1.11

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
1 Packages, Including:
tslib@2.6.2

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

39
All Dependencies CSV
β“˜ This is a list of pastash 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@pm2/io2.4.7152.21 kBMIT
prod
1
3
5
@qxip/bencode1.0.06.05 kBMIT
prod optional
amqplib0.5.168.42 kBMIT
prod optional
2
async2.6.0120.15 kBMIT
prod optional
1
aws-sdk2.112.03.03 MBApache-2.0
prod optional
5
1
1
csv-parser1.12.05.31 kBMIT
prod optional
fast-json-stringify0.17.012.66 kBMIT
prod optional
geoip-lite1.2.128.65 MBApache-2.0
prod optional
2
7
1
3
gun0.9.7400.01 kB(Zlib OR MIT OR Apache-2.0)
prod optional
4
hep-js1.0.2011.33 kBGPLv2
prod optional
1
1
hoek5.0.48.55 kBBSD-3-Clause
prod optional
2
http-proxy-agent2.1.06.95 kBMIT
prod optional
https-proxy-agent2.2.08.62 kBMIT
prod optional
1
json2csv4.5.4102.28 kBMIT
prod optional
1
kafka-node2.2.369.51 kBMIT
prod optional
4
7
1
2
log4node0.1.69.7 kBApache2
prod
1
1
lru-cache4.1.56.1 kBISC
prod
maxmind-geolite-mirror1.0.93.84 kBMIT
prod optional
maxmind0.6.058 kBMIT
prod optional
metrics-influxdb1.0.013.53 kBMIT
prod optional
1
mkdirp0.5.14.87 kBMIT
prod optional
1
1
1
modesl1.2.1663.6 kBUNKNOWN
prod optional
1
1
1
moment2.19.3548 kBMIT
prod optional
2
mqtt5.5.51.76 MBMIT
prod optional
msgpack1.0.398.72 kBUNKNOWN
prod optional
1
mustache2.3.022.07 kBMIT
prod optional
node-netflowv90.2.1620.01 kBGPLv2
prod optional
1
1
1
node-sflow0.0.69.95 kBGPLv2
prod optional
1
1
nsqjs0.10.142.42 kBMIT
prod optional
2
8
3
object.omit3.0.03.11 kBMIT
prod optional
oniguruma7.0.2570.89 kBMIT
prod optional
optimist0.6.112.06 kBMIT/X11
prod
1
1
1
1
qrelate1.0.93.33 kBMIT
prod optional
redis2.8.048.4 kBMIT
prod optional
1
splunk-logging0.9.314.39 kBApache-2.0
prod optional
3
2
sqlite33.1.133.97 MBBSD-3-Clause
prod optional
1
tinymath0.1.11102.89 kBApache 2
prod optional
2
1
ws4.0.022.47 kBMIT
prod optional
zmq2.15.3574.1 kBMIT
prod optional

Visualizations