Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 24, 2024 via pnpm
Package summary
Share
40
issues
3
critical severity
vulnerability
2
license
1
18
high severity
vulnerability
8
license
4
meta
6
12
moderate severity
vulnerability
7
license
1
meta
4
7
low severity
vulnerability
1
license
6
17
licenses
376
MIT
122
Apache-2.0
72
ISC
52
other licenses
BSD-2-Clause
22
BSD-3-Clause
11
0BSD
4
(MIT OR CC0-1.0)
4
+ 10 more
Package created
11 Jan 2017
Version published
13 Dec 2021
Maintainers
3
Total deps
622
Direct deps
77
License
AGPL-3.0

Issues

40

3 critical severity issues

critical
Recommendation: Upgrade to version 3.16.0 or later
via: simple-git@2.48.0
Recommendation: Upgrade to version 8.1.0 or later
via: git-url-parse@11.6.0
Recommendation: Check the package code and files for license information
via: json-dup-key-validator@1.0.3
Collapse
Expand

18 high severity issues

high
Recommendation: Upgrade to version 3.3.0 or later
via: simple-git@2.48.0
Recommendation: Upgrade to version 5.0.0 or later
via: git-url-parse@11.6.0
Recommendation: Upgrade to version 2.0.0 or later
via: parse-link-header@1.0.1
Recommendation: Upgrade to version 3.5.0 or later
via: simple-git@2.48.0
Recommendation: Upgrade to version 3.15.0 or later
via: simple-git@2.48.0
Recommendation: Upgrade to version 2.5.2 or later
via: luxon@2.1.1
Recommendation: Upgrade to version 3.0.5 or later
via: bunyan@1.8.15 & others
Recommendation: Upgrade to version 2.2.2 or later
via: json5@2.2.0
Recommendation: Validate that the license expression complies with your license policy
via: registry-auth-token@4.2.1
Recommendation: Validate that the package complies with your license policy
via: renovate@31.0.0
Recommendation: Validate that the package complies with your license policy
via: semver-utils@1.1.4
Recommendation: Read and validate the license terms
via: conventional-commits-detector@1.0.3
via: cacache@15.3.0 & others
via: @renovate/pep440@1.0.0
via: global-agent@2.2.0
via: marshal@0.5.2
via: bunyan@1.8.15
via: re2@1.17.1
Collapse
Expand

12 moderate severity issues

moderate
Recommendation: Upgrade to version 11.8.5 or later
via: @yarnpkg/core@2.4.0 & others
Recommendation: Upgrade to version 3.1.31 or later
via: nanoid@3.1.30
Recommendation: Upgrade to version 8.1.0 or later
via: git-url-parse@11.6.0
Recommendation: Upgrade to version 12.3.2 or later
via: markdown-it@12.2.0
Recommendation: Upgrade to version 5.10.1 or later
via: openpgp@5.0.1
Recommendation: Upgrade to version 4.1.2 or later
via: @aws-sdk/client-ec2@3.35.0 & others
Recommendation: Upgrade to version 7.5.2 or later
via: @yarnpkg/core@2.4.0 & others
Recommendation: Validate that the package complies with your license policy
via: openpgp@5.0.1
via: @yarnpkg/core@2.4.0
via: cacache@15.3.0 & others
via: cacache@15.3.0 & others
via: cacache@15.3.0 & others
Collapse
Expand

7 low severity issues

low
Recommendation: Upgrade to version 4.3.1 or later
via: marshal@0.5.2
Recommendation: Read and validate the license terms
via: auth-header@1.0.0
Recommendation: Read and validate the license terms
via: conventional-commits-detector@1.0.3
via: openpgp@5.0.1
via: renovate@31.0.0
Recommendation: Read and validate the license terms
via: semver-utils@1.1.4
Recommendation: Read and validate the license terms
via: conventional-commits-detector@1.0.3
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
376 Packages, Including:
@arcanis/slice-ansi@1.1.1
@babel/code-frame@7.24.2
@babel/helper-validator-identifier@7.24.5
@babel/highlight@7.24.5
@babel/runtime-corejs3@7.24.5
@breejs/later@4.1.0
@gar/promisify@1.1.3
@kwsites/file-exists@1.1.1
@kwsites/promise-deferred@1.1.1
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@npmcli/move-file@1.1.2
@renovatebot/parser-utils@1.0.0
@renovatebot/ruby-semver@1.0.0
@sindresorhus/is@4.2.0
@szmarczak/http-timer@4.0.6
@tootallnate/once@1.1.2
@types/cacheable-request@6.0.3
@types/emscripten@1.39.12
@types/http-cache-semantics@4.0.4
@types/keyv@3.1.4
@types/mdast@3.0.15
@types/minimist@1.2.5
@types/moo@0.5.5
@types/node@13.13.52
@types/node@20.12.12
@types/normalize-package-data@2.4.4
@types/redis@2.8.32
@types/responselike@1.0.3
@types/semver@7.5.8
@types/treeify@1.0.3
@types/unist@2.0.10
@types/yauzl@2.10.3
agent-base@6.0.2
agentkeepalive@4.5.0
aggregate-error@3.1.0
ansi-regex@5.0.1
ansi-styles@3.2.1
ansi-styles@4.3.0
any-promise@1.3.0
argparse@1.0.10
array-union@2.1.0
arrify@1.0.1
asap@2.0.6
asn1.js@5.4.1
azure-devops-node-api@11.1.0
bail@1.0.5
balanced-match@1.0.2
base64-js@1.5.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
122 Packages, Including:
@aws-crypto/ie11-detection@1.0.0
@aws-crypto/sha256-browser@1.2.2
@aws-crypto/sha256-js@1.2.2
@aws-crypto/supports-web-crypto@1.0.0
@aws-crypto/util@1.2.2
@aws-sdk/abort-controller@3.35.0
@aws-sdk/abort-controller@3.38.0
@aws-sdk/client-ec2@3.35.0
@aws-sdk/client-ecr@3.38.0
@aws-sdk/client-sso@3.35.0
@aws-sdk/client-sso@3.38.0
@aws-sdk/client-sts@3.35.0
@aws-sdk/client-sts@3.38.0
@aws-sdk/config-resolver@3.35.0
@aws-sdk/config-resolver@3.38.0
@aws-sdk/credential-provider-env@3.35.0
@aws-sdk/credential-provider-env@3.38.0
@aws-sdk/credential-provider-imds@3.35.0
@aws-sdk/credential-provider-imds@3.38.0
@aws-sdk/credential-provider-ini@3.35.0
@aws-sdk/credential-provider-ini@3.38.0
@aws-sdk/credential-provider-node@3.35.0
@aws-sdk/credential-provider-node@3.38.0
@aws-sdk/credential-provider-process@3.35.0
@aws-sdk/credential-provider-process@3.38.0
@aws-sdk/credential-provider-sso@3.35.0
@aws-sdk/credential-provider-sso@3.38.0
@aws-sdk/credential-provider-web-identity@3.35.0
@aws-sdk/credential-provider-web-identity@3.38.0
@aws-sdk/fetch-http-handler@3.35.0
@aws-sdk/fetch-http-handler@3.38.0
@aws-sdk/hash-node@3.35.0
@aws-sdk/hash-node@3.38.0
@aws-sdk/invalid-dependency@3.35.0
@aws-sdk/invalid-dependency@3.38.0
@aws-sdk/is-array-buffer@3.35.0
@aws-sdk/is-array-buffer@3.37.0
@aws-sdk/middleware-content-length@3.35.0
@aws-sdk/middleware-content-length@3.38.0
@aws-sdk/middleware-host-header@3.35.0
@aws-sdk/middleware-host-header@3.38.0
@aws-sdk/middleware-logger@3.35.0
@aws-sdk/middleware-logger@3.38.0
@aws-sdk/middleware-retry@3.35.0
@aws-sdk/middleware-retry@3.38.0
@aws-sdk/middleware-sdk-ec2@3.35.0
@aws-sdk/middleware-sdk-sts@3.35.0
@aws-sdk/middleware-sdk-sts@3.38.0
@aws-sdk/middleware-serde@3.35.0
@aws-sdk/middleware-serde@3.38.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
72 Packages, Including:
@iarna/toml@2.2.5
@npmcli/fs@1.1.1
abbrev@1.1.1
aproba@2.0.0
are-we-there-yet@3.0.1
boolbase@1.0.0
cacache@15.3.0
changelog-filename-regex@2.0.1
chownr@2.0.0
color-support@1.1.3
console-control-strings@1.1.0
deep-freeze-es6@1.4.1
fastq@1.17.1
fs-minipass@2.1.0
fs.realpath@1.0.0
gauge@4.0.4
glob-parent@5.1.2
glob@6.0.4
glob@7.2.3
graceful-fs@4.2.11
handy-redis@2.3.1
has-unicode@2.0.1
hosted-git-info@2.8.9
hosted-git-info@4.1.0
infer-owner@1.0.4
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
ini@2.0.0
isexe@2.0.0
json-stringify-safe@5.0.1
lru-cache@4.1.5
lru-cache@6.0.0
make-fetch-happen@9.1.0
minimalistic-assert@1.0.1
minimatch@3.0.4
minimatch@3.1.2
minipass-collect@1.0.2
minipass-flush@1.0.5
minipass-pipeline@1.2.4
minipass-sized@1.0.3
minipass@3.3.6
minipass@5.0.0
nopt@5.0.0
npmlog@6.0.2
once@1.3.3
once@1.4.0
picocolors@1.0.1
promise-inflight@1.0.1
pseudomap@1.0.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
22 Packages, Including:
@yarnpkg/core@2.4.0
@yarnpkg/fslib@2.10.4
@yarnpkg/json-proxy@2.1.1
@yarnpkg/libzip@2.3.0
@yarnpkg/parsers@2.4.1
@yarnpkg/pnp@2.3.2
@yarnpkg/shell@2.4.1
css-select@4.3.0
css-what@6.1.0
domelementtype@2.3.0
domhandler@4.3.1
domutils@2.8.0
dtrace-provider@0.8.8
entities@2.1.0
entities@2.2.0
esprima@4.0.1
extract-zip@2.0.1
http-cache-semantics@4.1.1
normalize-package-data@2.5.0
normalize-package-data@3.0.3
nth-check@2.1.1
uglify-js@3.17.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
11 Packages, Including:
diff@4.0.2
global-agent@2.2.0
ieee754@1.2.1
install-artifact-from-github@1.3.5
moo@0.5.1
qs@6.12.1
re2@1.17.1
roarr@2.15.4
source-map@0.6.1
sprintf-js@1.0.3
sprintf-js@1.1.3

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
4 Packages, Including:
tslib@1.14.1
tslib@2.1.0
tslib@2.3.1
tslib@2.6.2

(MIT OR CC0-1.0)

Public Domain
4 Packages, Including:
type-fest@0.13.1
type-fest@0.18.1
type-fest@0.6.0
type-fest@0.8.1

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
auth-header@1.0.0
spdx-license-ids@3.0.18

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

N/A

N/A
1 Packages, Including:
backslash@0.2.0

(MIT OR GPL-2.0)

Permissive
1 Packages, Including:
node.extend@2.0.3

GNU Lesser General Public License v3.0 or later

Weakly Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
use-patent-claims
Cannot
sublicense
hold-liable
Must
include-original
state-changes
disclose-source
include-license
include-copyright
include-install-instructions
1 Packages, Including:
openpgp@5.0.1

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

GNU Affero General Public License v3.0

Network Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
sublicense
hold-liable
Must
include-copyright
include-license
state-changes
disclose-source
include-install-instructions
1 Packages, Including:
renovate@31.0.0

APACHEv2

Invalid
Not OSI Approved
1 Packages, Including:
semver-utils@1.1.4

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
stream-buffers@3.0.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

77
All Dependencies CSV
β“˜ This is a list of renovate 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@aws-sdk/client-ec23.35.02.36 MBApache-2.0
prod
1
@aws-sdk/client-ecr3.38.0103.11 kBApache-2.0
prod
1
@breejs/later4.1.082.6 kBMIT
prod
@iarna/toml2.2.522.86 kBISC
prod
@renovate/pep4401.0.09.47 kBApache-2.0
prod
1
@renovatebot/parser-utils1.0.068.53 kBMIT
prod
@renovatebot/ruby-semver1.0.09.93 kBMIT
prod
@sindresorhus/is4.2.013.37 kBMIT
prod
@yarnpkg/core2.4.099.88 kBBSD-2-Clause
prod
3
@yarnpkg/parsers2.4.124.11 kBBSD-2-Clause
prod
auth-header1.0.06.76 kBCC0-1.0
prod
1
azure-devops-node-api11.1.0487.16 kBMIT
prod
bunyan1.8.1558.89 kBMIT
prod
2
cacache15.3.021.46 kBISC
prod optional
1
4
chalk4.1.211.31 kBMIT
prod
changelog-filename-regex2.0.11.81 kBISC
prod
clean-git-ref2.0.11.11 kBApache-2.0
prod
commander8.3.038.44 kBMIT
prod
conventional-commits-detector1.0.34.73 kBMIT
prod
1
1
2
crypto-random-string3.3.14.23 kBMIT
prod
deepmerge4.2.27.91 kBMIT
prod
delay5.0.03.96 kBMIT
prod
dequal2.0.24.22 kBMIT
prod
detect-indent6.1.03.92 kBMIT
prod
editorconfig0.15.318.28 kBMIT
prod
email-addresses5.0.023.69 kBMIT
prod
emoji-regex9.2.210.86 kBMIT
prod
emojibase-regex5.1.310.2 kBMIT
prod
emojibase5.2.022.86 kBMIT
prod
extract-zip2.0.14.26 kBBSD-2-Clause
prod
fast-safe-stringify2.1.17.71 kBMIT
prod
find-up5.0.03.72 kBMIT
prod
fs-extra10.0.032.9 kBMIT
prod
git-url-parse11.6.08.81 kBMIT
prod
1
1
1
github-url-from-git1.5.02.71 kBMIT
prod
global-agent2.2.029.83 kBBSD-3-Clause
prod
1
1
got11.8.366.03 kBMIT
prod
1
handlebars4.7.7617.76 kBMIT
prod
handy-redis2.3.160.48 kBISC
prod
hasha5.2.24.81 kBMIT
prod
ignore5.1.913.16 kBMIT
prod
ini2.0.03.99 kBISC
prod
js-yaml4.1.099.96 kBMIT
prod
json-dup-key-validator1.0.35.66 kBMIT
prod
1
json-stringify-pretty-compact3.0.03.89 kBMIT
prod
json52.2.053.98 kBMIT
prod
1
luxon2.1.1822.69 kBMIT
prod
1
markdown-it12.2.0153.19 kBMIT
prod
1
markdown-table2.0.04.76 kBMIT
prod
marshal0.5.28.92 kBMIT
prod
1
1
minimatch3.0.411.16 kBISC
prod optional
1
moo0.5.110.59 kBBSD-3-Clause
prod
nanoid3.1.305.28 kBMIT
prod
1
node-html-parser3.3.637.08 kBMIT
prod
openpgp5.0.15.1 MBLGPL-3.0+
prod
2
1
p-all3.0.02.57 kBMIT
prod
p-map4.0.03.36 kBMIT
prod
p-queue6.6.28.17 kBMIT
prod
parse-diff0.8.17.96 kBMIT
prod
parse-link-header1.0.13.24 kBMIT
prod
1
re21.17.1315.83 kBBSD-3-Clause
prod optional
2
4
redis3.1.245.79 kBMIT
prod
registry-auth-token4.2.14.33 kBMIT
prod
1
remark-github10.1.06.41 kBMIT
prod
remark13.0.03.08 kBMIT
prod
semver-stable3.0.02.36 kBMIT
prod
semver-utils1.1.44.09 kBAPACHEv2
prod
1
1
semver7.3.525.68 kBISC
prod optional
1
shlex2.1.06.72 kBMIT
prod
simple-git2.48.0103.38 kBMIT
prod
1
3
slugify1.6.36.68 kBMIT
prod
traverse0.6.610.94 kBMIT
prod
tslib2.3.17.85 kB0BSD
prod
upath2.0.18.13 kBMIT
prod
url-join4.0.15.64 kBMIT
prod
validate-npm-package-name3.0.05.25 kBISC
prod
xmldoc1.1.210.94 kBMIT
prod

Visualizations