Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 19, 2024 via pnpm
Package summary
Share
30
issues
2
critical severity
license
2
9
high severity
license
5
meta
4
11
moderate severity
license
2
meta
9
8
low severity
vulnerability
1
license
7
17
licenses
443
MIT
140
Apache-2.0
84
ISC
54
other licenses
BSD-2-Clause
25
BSD-3-Clause
10
(MIT OR CC0-1.0)
4
N/A
2
+ 10 more
Package created
11 Jan 2017
Version published
18 Sep 2023
Maintainers
3
Total deps
721
Direct deps
107
License
AGPL-3.0-only

Issues

30

2 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: @renovatebot/osv-offline@1.3.7
Recommendation: Check the package code and files for license information
via: json-dup-key-validator@1.0.3
Collapse
Expand

9 high severity issues

high
Recommendation: Read and validate the license terms
via: cacache@18.0.0 & others
Recommendation: Read and validate the license terms
via: cacache@18.0.0 & others
Recommendation: Validate that the package complies with your license policy
via: renovate@36.97.0
Recommendation: Validate that the package complies with your license policy
via: semver-utils@1.1.4
Recommendation: Read and validate the license terms
via: conventional-commits-detector@1.0.3
via: re2@1.20.3
via: @qnighy/marshal@0.1.3
via: bunyan@1.8.15
via: re2@1.20.3
Collapse
Expand

11 moderate severity issues

moderate
Recommendation: Validate that the package complies with your license policy
via: @cdktf/hcl2json@0.18.0
Recommendation: Validate that the package complies with your license policy
via: openpgp@5.10.1
via: @yarnpkg/core@3.5.3
via: @qnighy/marshal@0.1.3
via: redis@4.6.8
via: redis@4.6.8
via: redis@4.6.8
via: @renovatebot/osv-offline@1.3.7
via: cacache@18.0.0 & others
via: cacache@18.0.0 & others
via: find-packages@10.0.4
Collapse
Expand

8 low severity issues

low
Recommendation: Upgrade to version 3.22.3 or later
via: zod@3.22.2
Recommendation: Read and validate the license terms
via: auth-header@1.0.0
Recommendation: Read and validate the license terms
via: conventional-commits-detector@1.0.3
Recommendation: Read and validate the license terms
via: cacache@18.0.0 & others
Recommendation: Read and validate the license terms
via: cacache@18.0.0 & others
via: openpgp@5.10.1
Recommendation: Read and validate the license terms
via: semver-utils@1.1.4
Recommendation: Read and validate the license terms
via: conventional-commits-detector@1.0.3
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
443 Packages, Including:
@arcanis/slice-ansi@1.1.1
@babel/code-frame@7.23.5
@babel/helper-validator-identifier@7.22.20
@babel/highlight@7.23.4
@babel/runtime-corejs3@7.23.9
@breejs/later@4.1.0
@gar/promisify@1.1.3
@gwhitney/detect-indent@7.0.1
@kwsites/file-exists@1.1.1
@kwsites/promise-deferred@1.1.1
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@npmcli/move-file@2.0.1
@octokit/auth-token@3.0.4
@octokit/core@4.2.4
@octokit/endpoint@7.0.6
@octokit/graphql@5.0.6
@octokit/openapi-types@18.1.1
@octokit/plugin-paginate-rest@6.1.2
@octokit/plugin-request-log@1.0.4
@octokit/plugin-rest-endpoint-methods@7.2.3
@octokit/request-error@3.0.3
@octokit/request@6.2.8
@octokit/rest@19.0.13
@octokit/tsconfig@1.0.2
@octokit/types@10.0.0
@octokit/types@9.3.2
@one-ini/wasm@0.1.1
@pkgjs/parseargs@0.11.0
@pnpm/constants@6.1.0
@pnpm/error@4.0.0
@pnpm/graceful-fs@2.0.0
@pnpm/read-project-manifest@4.1.1
@pnpm/text.comments-parser@1.0.0
@pnpm/types@8.9.0
@pnpm/util.lex-comparator@1.0.0
@pnpm/write-project-manifest@4.1.1
@qnighy/marshal@0.1.3
@redis/bloom@1.2.0
@redis/client@1.5.9
@redis/graph@1.1.0
@redis/json@1.0.4
@redis/search@1.1.3
@redis/time-series@1.0.5
@renovatebot/osv-offline-db@1.4.0
@renovatebot/osv-offline@1.3.7
@renovatebot/ruby-semver@3.0.14
@seald-io/nedb@4.0.4
@sindresorhus/is@4.6.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
140 Packages, Including:
@aws-crypto/crc32@3.0.0
@aws-crypto/crc32c@3.0.0
@aws-crypto/ie11-detection@3.0.0
@aws-crypto/sha1-browser@3.0.0
@aws-crypto/sha256-browser@3.0.0
@aws-crypto/sha256-js@3.0.0
@aws-crypto/supports-web-crypto@3.0.0
@aws-crypto/util@3.0.0
@aws-sdk/chunked-blob-reader@3.310.0
@aws-sdk/client-codecommit@3.363.0
@aws-sdk/client-cognito-identity@3.363.0
@aws-sdk/client-ec2@3.363.0
@aws-sdk/client-ecr@3.363.0
@aws-sdk/client-rds@3.363.0
@aws-sdk/client-s3@3.363.0
@aws-sdk/client-sso-oidc@3.363.0
@aws-sdk/client-sso@3.363.0
@aws-sdk/client-sts@3.363.0
@aws-sdk/credential-provider-cognito-identity@3.363.0
@aws-sdk/credential-provider-env@3.363.0
@aws-sdk/credential-provider-ini@3.363.0
@aws-sdk/credential-provider-node@3.363.0
@aws-sdk/credential-provider-process@3.363.0
@aws-sdk/credential-provider-sso@3.363.0
@aws-sdk/credential-provider-web-identity@3.363.0
@aws-sdk/credential-providers@3.363.0
@aws-sdk/hash-blob-browser@3.357.0
@aws-sdk/hash-stream-node@3.357.0
@aws-sdk/is-array-buffer@3.310.0
@aws-sdk/md5-js@3.357.0
@aws-sdk/middleware-bucket-endpoint@3.363.0
@aws-sdk/middleware-expect-continue@3.363.0
@aws-sdk/middleware-flexible-checksums@3.363.0
@aws-sdk/middleware-host-header@3.363.0
@aws-sdk/middleware-location-constraint@3.363.0
@aws-sdk/middleware-logger@3.363.0
@aws-sdk/middleware-recursion-detection@3.363.0
@aws-sdk/middleware-sdk-ec2@3.363.0
@aws-sdk/middleware-sdk-rds@3.363.0
@aws-sdk/middleware-sdk-s3@3.363.0
@aws-sdk/middleware-sdk-sts@3.363.0
@aws-sdk/middleware-signing@3.363.0
@aws-sdk/middleware-ssec@3.363.0
@aws-sdk/middleware-user-agent@3.363.0
@aws-sdk/signature-v4-multi-region@3.363.0
@aws-sdk/token-providers@3.363.0
@aws-sdk/types@3.357.0
@aws-sdk/util-arn-parser@3.310.0
@aws-sdk/util-buffer-from@3.310.0
@aws-sdk/util-endpoints@3.357.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
84 Packages, Including:
@iarna/toml@3.0.0
@isaacs/cliui@8.0.2
@npmcli/fs@2.1.2
@npmcli/fs@3.1.0
abbrev@1.1.1
aproba@2.0.0
are-we-there-yet@3.0.1
boolbase@1.0.0
cacache@16.1.3
cacache@18.0.0
changelog-filename-regex@2.0.1
chownr@2.0.0
color-support@1.1.3
console-control-strings@1.1.0
deprecation@2.3.1
fastq@1.17.1
foreground-child@3.1.1
fs-minipass@2.1.0
fs-minipass@3.0.3
fs.realpath@1.0.0
gauge@4.0.4
glob-parent@5.1.2
glob@10.3.4
glob@6.0.4
glob@7.2.3
glob@8.1.0
graceful-fs@4.2.11
has-unicode@2.0.1
hosted-git-info@2.8.9
hosted-git-info@4.1.0
infer-owner@1.0.4
inflight@1.0.6
inherits@2.0.4
ini@4.1.1
isexe@2.0.0
json-stringify-safe@5.0.1
lru-cache@10.2.0
lru-cache@6.0.0
lru-cache@7.18.3
make-fetch-happen@10.2.1
minimalistic-assert@1.0.1
minimatch@3.1.2
minimatch@5.1.6
minimatch@9.0.2
minimatch@9.0.3
minipass-collect@1.0.2
minipass-flush@1.0.5
minipass-pipeline@1.2.4
minipass-sized@1.0.3
minipass@3.3.6

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
25 Packages, Including:
@yarnpkg/core@3.5.3
@yarnpkg/fslib@2.10.4
@yarnpkg/json-proxy@2.1.1
@yarnpkg/libzip@2.3.0
@yarnpkg/parsers@2.5.1
@yarnpkg/parsers@2.6.0
@yarnpkg/pnp@3.3.7
@yarnpkg/shell@3.3.0
css-select@5.1.0
css-what@6.1.0
domelementtype@2.3.0
domhandler@5.0.3
domutils@3.1.0
dtrace-provider@0.8.8
entities@3.0.1
entities@4.5.0
esprima@4.0.1
extract-zip@2.0.1
http-cache-semantics@4.1.1
normalize-package-data@2.5.0
normalize-package-data@3.0.3
nth-check@2.1.1
shimmer@1.2.1
uglify-js@3.17.4
webidl-conversions@3.0.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
10 Packages, Including:
diff@5.2.0
global-agent@3.0.0
install-artifact-from-github@1.3.5
moo@0.5.2
qs@6.11.2
re2@1.20.3
roarr@2.15.4
source-map@0.6.1
sprintf-js@1.0.3
sprintf-js@1.1.3

(MIT OR CC0-1.0)

Public Domain
4 Packages, Including:
type-fest@0.13.1
type-fest@0.18.1
type-fest@0.6.0
type-fest@0.8.1

N/A

N/A
2 Packages, Including:
@seald-io/binary-search-tree@1.0.3
backslash@0.2.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
auth-header@1.0.0
spdx-license-ids@3.0.17

Blue Oak Model License 1.0.0

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
jackspeak@2.3.6
path-scurry@1.10.1

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

Mozilla Public License 2.0

Weakly Protective
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
place-warranty
use-patent-claims
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
disclose-source
include-original
1 Packages, Including:
@cdktf/hcl2json@0.18.0

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

(MIT OR GPL-2.0)

Permissive
1 Packages, Including:
node.extend@2.0.3

GNU Lesser General Public License v3.0 or later

Weakly Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
use-patent-claims
Cannot
sublicense
hold-liable
Must
include-original
state-changes
disclose-source
include-license
include-copyright
include-install-instructions
1 Packages, Including:
openpgp@5.10.1

GNU Affero General Public License v3.0 only

Network Protective
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
sublicense
hold-liable
Must
include-copyright
include-license
state-changes
disclose-source
include-install-instructions
1 Packages, Including:
renovate@36.97.0

APACHEv2

Invalid
Not OSI Approved
1 Packages, Including:
semver-utils@1.1.4

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

107
All Dependencies CSV
β“˜ This is a list of renovate 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@aws-sdk/client-codecommit3.363.0199.92 kBApache-2.0
prod
@aws-sdk/client-ec23.363.01.34 MBApache-2.0
prod
@aws-sdk/client-ecr3.363.096.03 kBApache-2.0
prod
@aws-sdk/client-rds3.363.0460.67 kBApache-2.0
prod
@aws-sdk/client-s33.363.0306.19 kBApache-2.0
prod
@aws-sdk/credential-providers3.363.018.25 kBApache-2.0
prod
@breejs/later4.1.082.6 kBMIT
prod
@cdktf/hcl2json0.18.01.62 MBMPL-2.0
prod
1
@iarna/toml3.0.022.81 kBISC
prod
@opentelemetry/api1.6.0106.12 kBApache-2.0
prod peer
@opentelemetry/context-async-hooks1.17.013.52 kBApache-2.0
prod
@opentelemetry/exporter-trace-otlp-http0.43.013.16 kBApache-2.0
prod
@opentelemetry/instrumentation-bunyan0.32.18.9 kBApache-2.0
prod
@opentelemetry/instrumentation-http0.43.036.63 kBApache-2.0
prod
@opentelemetry/instrumentation0.43.041.26 kBApache-2.0
prod
@opentelemetry/resources1.17.051.31 kBApache-2.0
prod
@opentelemetry/sdk-trace-base1.17.079.98 kBApache-2.0
prod
@opentelemetry/sdk-trace-node1.17.08.74 kBApache-2.0
prod
@opentelemetry/semantic-conventions1.17.0120.14 kBApache-2.0
prod
@qnighy/marshal0.1.36.8 kBMIT
prod
1
1
@renovatebot/osv-offline1.3.73.47 kBMIT
prod
1
1
@renovatebot/pep4403.0.710.46 kBApache-2.0
prod
@renovatebot/ruby-semver3.0.1410 kBMIT
prod
@sindresorhus/is4.6.013.95 kBMIT
prod
@types/ms0.7.311.57 kBMIT
prod
@types/tmp0.2.33.36 kBMIT
prod
@yarnpkg/core3.5.3249.3 kBBSD-2-Clause
prod
1
@yarnpkg/parsers2.5.124.79 kBBSD-2-Clause
prod
agentkeepalive4.5.012.86 kBMIT
prod optional
aggregate-error3.1.02.59 kBMIT
prod
auth-header1.0.06.76 kBCC0-1.0
prod
1
aws41.12.08.06 kBMIT
prod
azure-devops-node-api12.1.0507.55 kBMIT
prod
bunyan1.8.1558.89 kBMIT
prod
1
cacache18.0.018.88 kBISC
prod
2
2
2
cacheable-lookup5.0.47.06 kBMIT
prod
chalk4.1.211.31 kBMIT
prod
changelog-filename-regex2.0.11.81 kBISC
prod
clean-git-ref2.0.11.11 kBApache-2.0
prod
commander11.0.044.33 kBMIT
prod
conventional-commits-detector1.0.34.73 kBMIT
prod
1
2
cron-parser4.9.013.39 kBMIT
prod
deepmerge4.3.18.25 kBMIT
prod
dequal2.0.34.19 kBMIT
prod
detect-indent6.1.03.92 kBMIT
prod
editorconfig2.0.010.58 kBMIT
prod
email-addresses5.0.023.69 kBMIT
prod
emoji-regex10.2.14.95 kBMIT
prod
emojibase-regex15.0.027.91 kBMIT
prod
emojibase15.0.026.78 kBMIT
prod
extract-zip2.0.14.26 kBBSD-2-Clause
prod
find-packages10.0.43.63 kBMIT
prod
1
find-up5.0.03.72 kBMIT
prod
fs-extra11.1.115.45 kBMIT
prod
git-url-parse13.1.09.33 kBMIT
prod
github-url-from-git1.5.02.71 kBMIT
prod
glob10.3.466.38 kBISC
prod
2
2
global-agent3.0.029.83 kBBSD-3-Clause
prod
good-enough-parser1.1.2384.86 kBMIT
prod
got11.8.666.14 kBMIT
prod
graph-data-structure3.3.016.87 kBMIT
prod
handlebars4.7.8632 kBMIT
prod
hasha5.2.24.81 kBMIT
prod
ignore5.2.414.04 kBMIT
prod
ini4.1.14.99 kBISC
prod
js-yaml4.1.099.96 kBMIT
prod
json-dup-key-validator1.0.35.66 kBMIT
prod
1
json-stringify-pretty-compact3.0.03.89 kBMIT
prod
json52.2.349.14 kBMIT
prod
jsonata2.0.3182.71 kBMIT
prod
klona2.0.65.86 kBMIT
prod
luxon3.4.3868.65 kBMIT
prod
markdown-it13.0.1149.68 kBMIT
prod
markdown-table2.0.04.76 kBMIT
prod
minimatch9.0.393.35 kBISC
prod
moo0.5.210.82 kBBSD-3-Clause
prod
ms2.1.32.9 kBMIT
prod
nanoid3.3.65.32 kBMIT
prod
node-html-parser6.1.1033.62 kBMIT
prod
openpgp5.10.15.17 MBLGPL-3.0+
prod
1
1
p-all3.0.02.57 kBMIT
prod
p-map4.0.03.36 kBMIT
prod optional
p-queue6.6.28.17 kBMIT
prod
p-throttle4.1.13.24 kBMIT
prod
parse-link-header2.0.03.63 kBMIT
prod
prettier2.8.82.61 MBMIT
prod
quick-lru5.1.13.31 kBMIT
prod
re21.20.32.4 MBBSD-3-Clause
prod optional
2
2
redis4.6.89.25 kBMIT
prod
3
remark-github10.1.06.41 kBMIT
prod
remark13.0.03.08 kBMIT
prod
safe-stable-stringify2.4.36.97 kBMIT
prod
semver-stable3.0.02.36 kBMIT
prod
semver-utils1.1.44.09 kBAPACHEv2
prod
1
1
semver7.5.426.25 kBISC
prod optional
shlex2.1.27.06 kBMIT
prod
simple-git3.19.1199.99 kBMIT
prod
slugify1.6.68.5 kBMIT
prod
source-map-support0.5.2126.03 kBMIT
prod
traverse0.6.722.67 kBMIT
prod
tslib2.6.215.59 kB0BSD
prod
upath2.0.18.13 kBMIT
prod
url-join4.0.15.64 kBMIT
prod
validate-npm-package-name5.0.03.11 kBISC
prod
vuln-vects1.1.0289.37 kBMIT
prod
xmldoc1.3.011.47 kBMIT
prod
zod3.22.2101.86 kBMIT
prod
1

Visualizations