Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 27, 2024 via pnpm

react-color-picker 2.0.1

React Color Picker
Package summary
Share
20
issues
3
critical severity
vulnerability
1
license
2
11
high severity
vulnerability
2
license
6
meta
3
6
low severity
license
6
9
licenses
95
MIT
8
ISC
6
BSD-3-Clause
12
other licenses
BSD
5
N/A
2
Apache-2.0
2
BSD-3-Clause OR MIT
1
+ 2 more
Package created
15 Oct 2014
Version published
5 Nov 2014
Maintainers
1
Total deps
121
Direct deps
7
License
MIT

Issues

20

3 critical severity issues

critical
Recommendation: Upgrade to version 1.4.1 or later
via: jsx-loader@0.12.2
Recommendation: Check the package code and files for license information
via: gulp-react@2.0.0 & others
Recommendation: Check the package code and files for license information
via: tinycolor2@1.0.0
Collapse
Expand

11 high severity issues

high
Recommendation: Upgrade to version 0.14.0 or later
via: react@0.12.2
Recommendation: Upgrade to version 1.0.2 or later
via: jsx-loader@0.12.2
Recommendation: Validate that the package complies with your license policy
via: gulp-react@2.0.0
Recommendation: Validate that the package complies with your license policy
via: jsx-loader@0.12.2
Recommendation: Validate that the package complies with your license policy
via: react@0.12.2
Recommendation: Validate that the package complies with your license policy
via: gulp-react@2.0.0
Recommendation: Validate that the package complies with your license policy
via: gulp-react@2.0.0 & others
Recommendation: Validate that the package complies with your license policy
via: jsx-loader@0.12.2
via: gulp-react@2.0.0
via: gulp-react@2.0.0
via: jsx-loader@0.12.2
Collapse
Expand

6 low severity issues

low
Recommendation: Read and validate the license terms
via: gulp-react@2.0.0
Recommendation: Read and validate the license terms
via: jsx-loader@0.12.2
Recommendation: Read and validate the license terms
via: react@0.12.2
Recommendation: Read and validate the license terms
via: gulp-react@2.0.0
Recommendation: Read and validate the license terms
via: gulp-react@2.0.0 & others
Recommendation: Read and validate the license terms
via: jsx-loader@0.12.2
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
95 Packages, Including:
acorn@5.7.4
ansi-gray@0.1.1
ansi-regex@2.1.1
ansi-styles@2.2.1
ansi-wrap@0.1.0
array-differ@1.0.0
array-uniq@1.0.3
ast-types@0.9.6
balanced-match@1.0.2
base62@1.2.8
beeper@1.1.1
big.js@3.2.0
brace-expansion@1.1.11
chalk@1.1.3
classy@1.4.10
clone-stats@0.0.1
clone@1.0.4
commander@2.20.3
commoner@0.10.8
concat-map@0.0.1
copy-utils@0.1.1
copy-utils@1.0.0
core-util-is@1.0.3
dateformat@2.2.0
defined@1.0.1
detective@4.7.1
emojis-list@2.1.0
envify@3.4.1
escape-string-regexp@1.0.5
fancy-log@1.3.3
fn-queue@0.2.1
functionally@0.6.2
glogg@1.0.2
gulp-react@2.0.0
gulp-util@3.0.8
gulplog@1.0.0
has-ansi@2.0.0
has-gulplog@0.1.0
hasown@1.0.1
i-s@1.2.3
iconv-lite@0.4.24
isarray@0.0.1
isarray@1.0.0
json5@0.5.1
loader-utils@0.2.17
lodash._basecopy@3.0.1
lodash._basetostring@3.0.1
lodash._basevalues@3.0.0
lodash._getnative@3.9.1
lodash._isiterateecall@3.0.9

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
8 Packages, Including:
color-support@1.1.3
glob@5.0.15
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
minimatch@3.1.2
once@1.4.0
wrappy@1.0.2

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
6 Packages, Including:
jstransform@11.0.3
react-tools@0.12.2
react-tools@0.13.3
react@0.12.2
source-map@0.4.4
source-map@0.5.7

BSD

Invalid
Not OSI Approved
5 Packages, Including:
duplexer2@0.0.2
esprima-fb@13001.1001.0-dev-harmony-fb
esprima-fb@15001.1.0-dev-harmony-fb
esprima-fb@8001.1001.0-dev-harmony-fb
source-map@0.1.31

N/A

N/A
2 Packages, Including:
base62@0.1.1
tinycolor2@1.0.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
jstransform@10.1.0
jstransform@8.2.0

BSD-3-Clause OR MIT

Permissive
1 Packages, Including:
amdefine@1.0.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
esprima@3.1.3

Apache 2

Invalid
Not OSI Approved
1 Packages, Including:
jsx-loader@0.12.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

7
All Dependencies CSV
β“˜ This is a list of react-color-picker 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
copy-utils1.0.09.07 kBMIT
prod
functionally0.6.214.86 kBMIT
prod
gulp-react2.0.01.27 kBMIT
prod
1
5
3
jsx-loader0.12.2965 BApache 2
prod
2
5
3
react0.12.2582.8 kBBSD-3-Clause
prod
2
1
region1.1.519.66 kBMIT
prod
tinycolor21.0.0135.67 kBUNKNOWN
prod
1

Visualizations