Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 15, 2024 via pnpm

react-pdf 5.7.0

Display PDFs in your React app as easily as if they were images.
Package summary
Share
5
issues
4
high severity
vulnerability
3
license
1
1
low severity
license
1
6
licenses
84
MIT
7
BSD-2-Clause
3
Apache-2.0
7
other licenses
BSD-3-Clause
3
ISC
3
CC-BY-4.0
1
Package created
30 Sep 2014
Version published
27 Jan 2022
Maintainers
1
Total deps
101
Direct deps
12
License
MIT

Issues

5

4 high severity issues

high
Recommendation: Upgrade to version 7.7.3 or later
via: react-pdf@5.7.0
Recommendation: Upgrade to version 4.2.67 or later
via: pdfjs-dist@2.12.313
Recommendation: Upgrade to version 7.7.3 or later
via: react-pdf@5.7.0
Recommendation: Read and validate the license terms
via: file-loader@6.2.0
Collapse
Expand

1 low severity issue

low
Recommendation: Read and validate the license terms
via: file-loader@6.2.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
84 Packages, Including:
@babel/runtime@7.24.5
@jridgewell/gen-mapping@0.3.5
@jridgewell/resolve-uri@3.1.2
@jridgewell/set-array@1.2.1
@jridgewell/source-map@0.3.6
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.25
@types/eslint-scope@3.7.7
@types/eslint@8.56.10
@types/estree@1.0.5
@types/json-schema@7.0.15
@types/node@20.12.12
@webassemblyjs/ast@1.12.1
@webassemblyjs/floating-point-hex-parser@1.11.6
@webassemblyjs/helper-api-error@1.11.6
@webassemblyjs/helper-buffer@1.12.1
@webassemblyjs/helper-numbers@1.11.6
@webassemblyjs/helper-wasm-bytecode@1.11.6
@webassemblyjs/helper-wasm-section@1.12.1
@webassemblyjs/ieee754@1.11.6
@webassemblyjs/utf8@1.11.6
@webassemblyjs/wasm-edit@1.12.1
@webassemblyjs/wasm-gen@1.12.1
@webassemblyjs/wasm-opt@1.12.1
@webassemblyjs/wasm-parser@1.12.1
@webassemblyjs/wast-printer@1.12.1
acorn-import-assertions@1.9.0
acorn@8.11.3
ajv-keywords@3.5.2
ajv@6.12.6
big.js@5.2.2
browserslist@4.23.0
buffer-from@1.1.2
chrome-trace-event@1.0.3
commander@2.20.3
emojis-list@3.0.0
enhanced-resolve@5.16.1
es-module-lexer@1.5.2
escalade@3.1.2
events@3.3.0
fast-deep-equal@3.1.3
fast-json-stable-stringify@2.1.0
file-loader@6.2.0
has-flag@4.0.0
jest-worker@27.5.1
js-tokens@4.0.0
json-parse-even-better-errors@2.3.1
json-schema-traverse@0.4.1
json5@2.2.3
loader-runner@4.3.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
7 Packages, Including:
eslint-scope@5.1.1
esrecurse@4.3.0
estraverse@4.3.0
estraverse@5.3.0
glob-to-regexp@0.4.1
terser@5.31.0
uri-js@4.4.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
3 Packages, Including:
@webassemblyjs/leb128@1.11.6
@xtuc/long@4.2.2
pdfjs-dist@2.12.313

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
@xtuc/ieee754@1.2.0
serialize-javascript@6.0.2
source-map@0.6.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
electron-to-chromium@1.4.769
graceful-fs@4.2.11
picocolors@1.0.1

Creative Commons Attribution 4.0 International

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
caniuse-lite@1.0.30001618
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

12
All Dependencies CSV
β“˜ This is a list of react-pdf 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@babel/runtime7.24.5256.12 kBMIT
prod
file-loader6.2.09.82 kBMIT
prod
1
1
make-cancellable-promise1.3.23.25 kBMIT
prod
make-event-props1.6.27.68 kBMIT
prod
merge-class-names1.4.22.62 kBMIT
prod
merge-refs1.3.010.08 kBMIT
prod
pdfjs-dist2.12.3139.36 MBApache-2.0
prod
1
prop-types15.8.122.12 kBMIT
prod
react-dom18.3.14.3 MBMIT
prod peer
react18.3.1310.65 kBMIT
prod peer
tiny-invariant1.3.314.46 kBMIT
prod
tiny-warning1.0.33.66 kBMIT
prod

Visualizations