Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 4, 2024 via pnpm
Package summary
Share
27
issues
3
critical severity
vulnerability
1
license
2
15
high severity
vulnerability
2
license
4
meta
9
4
moderate severity
vulnerability
2
meta
2
5
low severity
vulnerability
2
license
3
10
licenses
177
MIT
15
ISC
5
BSD-3-Clause
13
other licenses
BSD-2-Clause
4
MIT/X11
2
N/A
2
Apache-2.0
2
+ 3 more
Package created
17 Feb 2018
Version published
18 Feb 2018
Maintainers
1
Total deps
210
Direct deps
28
License
AGPL-3.0

Issues

27

3 critical severity issues

critical
Recommendation: Upgrade to version 0.2.4 or later
via: mkdirp@0.5.1
Recommendation: Check the package code and files for license information
via: cli-table-redemption@1.0.1
Recommendation: Check the package code and files for license information
via: pm2-axon@3.1.0
Collapse
Expand

15 high severity issues

high
Recommendation: Upgrade to version 5.1.2 or later
via: chokidar@1.7.0
Recommendation: Upgrade to version 0.8.5 or later
via: shelljs@0.7.8
Recommendation: Validate that the package complies with your license policy
via: pm2-multimeter@0.1.2
Recommendation: Validate that the package complies with your license policy
via: pm2-multimeter@0.1.2
Recommendation: Validate that the package complies with your license policy
via: pm2-fix@2.9.6
Recommendation: Validate that the license expression complies with your license policy
via: pm2-deploy@0.3.10
via: chokidar@1.7.0
via: chokidar@1.7.0
via: chokidar@1.7.0
via: mkdirp@0.5.1
via: chokidar@1.7.0
via: chokidar@1.7.0
via: chokidar@1.7.0
via: chokidar@1.7.0
via: pmx@1.5.6
Collapse
Expand

4 moderate severity issues

moderate
Recommendation: Upgrade to version 0.8.5 or later
via: shelljs@0.7.8
Recommendation: Upgrade to version 0.2.1 or later
via: mkdirp@0.5.1
via: pm2-axon@3.1.0
via: v8-compile-cache@1.1.2
Collapse
Expand

5 low severity issues

low
Recommendation: Upgrade to version 2.3.1 or later
via: chokidar@1.7.0
Recommendation: Upgrade to version 2.3.1 or later
via: chokidar@1.7.0
Recommendation: Read and validate the license terms
via: pm2-multimeter@0.1.2
Recommendation: Read and validate the license terms
via: pm2-multimeter@0.1.2
via: pm2-fix@2.9.6
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
177 Packages, Including:
amp-message@0.1.2
amp@0.3.1
ansi-regex@2.1.1
ansi-styles@2.2.1
argparse@1.0.10
arr-diff@2.0.0
arr-diff@4.0.0
arr-flatten@1.1.0
arr-union@3.1.0
array-unique@0.2.1
array-unique@0.3.2
assign-symbols@1.0.0
async-each@1.0.6
async@1.5.2
async@2.6.4
balanced-match@1.0.2
base@0.11.2
binary-extensions@1.13.1
bindings@1.5.0
blessed@0.1.81
brace-expansion@1.1.11
braces@1.8.5
braces@2.3.2
buffer-from@1.1.2
cache-base@1.0.1
chalk@1.1.3
chokidar@1.7.0
class-utils@0.3.6
collection-visit@1.0.0
commander@2.12.2
component-emitter@1.3.1
concat-map@0.0.1
copy-descriptor@0.1.1
core-util-is@1.0.3
cron@1.8.2
debug@2.6.9
debug@3.2.7
decode-uri-component@0.2.2
define-property@0.2.5
define-property@1.0.0
define-property@2.0.2
escape-string-regexp@1.0.5
eventemitter2@0.4.14
eventemitter2@1.0.5
expand-brackets@0.1.5
expand-brackets@2.1.4
expand-range@1.8.2
extend-shallow@2.0.1
extend-shallow@3.0.2
extend@3.0.2

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
15 Packages, Including:
anymatch@1.3.2
fs.realpath@1.0.0
glob-parent@2.0.0
glob@7.2.3
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
json-stringify-safe@5.0.1
minimatch@3.1.2
mute-stream@0.0.8
once@1.4.0
read@1.0.7
remove-trailing-separator@1.1.0
semver@5.7.2
wrappy@1.0.2

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
shelljs@0.7.8
source-map@0.5.7
source-map@0.6.1
sprintf-js@1.0.3
sprintf-js@1.1.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
4 Packages, Including:
async-listener@0.6.10
continuation-local-storage@3.2.1
emitter-listener@1.1.2
shimmer@1.2.1

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
charm@0.1.2
pm2-multimeter@0.1.2

N/A

N/A
2 Packages, Including:
cli-table-redemption@1.0.1
escape-regexp@0.0.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
vizion@0.2.13
vxx@1.2.2

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

GNU Affero General Public License v3.0

Network Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
sublicense
hold-liable
Must
include-copyright
include-license
state-changes
disclose-source
include-install-instructions
1 Packages, Including:
pm2-fix@2.9.6

(Public Domain OR MIT)

Expression
1 Packages, Including:
tv4@1.3.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

28
All Dependencies CSV
β“˜ This is a list of pm2-fix 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
async2.6.4120.04 kBMIT
prod
blessed0.1.81255.48 kBMIT
prod
chalk1.1.35.11 kBMIT
prod
chokidar1.7.022.33 kBMIT
prod
8
2
cli-table-redemption1.0.16.54 kBUNKNOWN
prod
1
commander2.12.216.39 kBMIT
prod
cron1.8.217.53 kBMIT
prod
debug3.2.716.48 kBMIT
prod
eventemitter21.0.58.51 kBMIT
prod
fclone1.0.114.53 kBMIT
prod
mkdirp0.5.14.87 kBMIT
prod
1
1
1
moment2.30.1698.76 kBMIT
prod
needle1.6.039.69 kBMIT
prod
nssocket0.6.013.86 kBMIT
prod
pidusage1.2.09.69 kBMIT
prod
pm2-axon-rpc0.5.03.59 kBMIT
prod
pm2-axon3.1.013.72 kBMIT
prod
1
1
pm2-deploy0.3.105.78 kBMIT
prod
1
pm2-multimeter0.1.23.87 kBMIT/X11
prod
2
2
pmx1.5.623.58 kBMIT
prod
1
promptly2.2.05.66 kBMIT
prod
semver5.7.217.45 kBISC
prod
shelljs0.7.851.34 kBBSD-3-Clause
prod
1
1
source-map-support0.5.2126.03 kBMIT
prod
sprintf-js1.1.113.29 kBBSD-3-Clause
prod
v8-compile-cache1.1.24.52 kBMIT
prod
1
vizion0.2.137.25 kBApache-2.0
prod
yamljs0.3.0150.28 kBMIT
prod

Visualizations