Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Feb 27, 2024 via pnpm

sails 1.0.2

API-driven framework for building realtime apps, using MVC conventions (based on Express and Socket.io)
Package summary
Share
39
issues
12
critical severity
vulnerability
7
license
5
15
high severity
vulnerability
8
license
5
meta
2
8
moderate severity
vulnerability
4
meta
4
4
low severity
vulnerability
1
license
3
8
licenses
228
MIT
26
ISC
5
N/A
8
other licenses
BSD-3-Clause
2
(BSD-2-Clause OR MIT OR Apache-2.0)
2
MIT/X11
2
Apache-2.0
1
+ 1 more
Package created
16 Jan 2013
Version published
6 May 2018
Maintainers
4
Total deps
267
Direct deps
44
License
MIT

Issues

39

12 critical severity issues

critical
Recommendation: None
via: sails@1.0.2
Recommendation: None
via: sails@1.0.2
Recommendation: Upgrade to version 3.1.7 or later
via: ejs@2.5.7
Recommendation: Upgrade to version 6.0.0 or later
via: machinepack-process@2.0.2
Recommendation: Upgrade to version 4.17.12 or later
via: machinepack-process@2.0.2 & others
Recommendation: Upgrade to version 0.5.1 or later
via: rc@1.2.2
Recommendation: Upgrade to version 0.2.4 or later
via: minimist@0.0.10
Recommendation: Check the package code and files for license information
via: prompt@0.2.14
Recommendation: Check the package code and files for license information
via: prompt@0.2.14
Recommendation: Check the package code and files for license information
via: skipper@0.8.7
Recommendation: Check the package code and files for license information
via: prompt@0.2.14
Recommendation: Check the package code and files for license information
via: prompt@0.2.14
Collapse
Expand

15 high severity issues

high
Recommendation: Upgrade to version 1.5.7 or later
via: sails@1.0.2
Recommendation: Upgrade to version 3.1.1 or later
via: machinepack-redis@1.3.0
Recommendation: Upgrade to version 4.17.11 or later
via: machinepack-process@2.0.2 & others
Recommendation: Upgrade to version 1.5.7 or later
via: sails@1.0.2
Recommendation: Upgrade to version 4.17.19 or later
via: machinepack-process@2.0.2 & others
Recommendation: Upgrade to version 6.5.3 or later
via: express@4.16.2 & others
Recommendation: Upgrade to version 2.6.4 or later
via: async@2.5.0 & others
Recommendation: Upgrade to version 4.17.21 or later
via: machinepack-process@2.0.2 & others
Recommendation: Validate that the license expression complies with your license policy
via: rc@1.2.2
Recommendation: Validate that the license expression complies with your license policy
via: captains-log@2.0.4 & others
Recommendation: Validate that the package complies with your license policy
via: whelk@6.0.1
Recommendation: Validate that the package complies with your license policy
via: whelk@6.0.1
Recommendation: Validate that the package complies with your license policy
via: prompt@0.2.14
via: i18n-2@0.6.3
via: skipper@0.8.7
Collapse
Expand

8 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: machinepack-process@2.0.2 & others
Recommendation: Upgrade to version 4.17.21 or later
via: machinepack-process@2.0.2 & others
Recommendation: Upgrade to version 0.2.1 or later
via: minimist@0.0.10
Recommendation: Upgrade to version 5.7.2 or later
via: semver@4.3.6 & others
via: prompt@0.2.14
via: include-all@4.0.3
via: merge-dictionaries@1.0.0
via: sort-route-addresses@0.0.1
Collapse
Expand

4 low severity issues

low
Recommendation: Upgrade to version 4.17.5 or later
via: machinepack-process@2.0.2 & others
Recommendation: Read and validate the license terms
via: whelk@6.0.1
Recommendation: Read and validate the license terms
via: whelk@6.0.1
Recommendation: Read and validate the license terms
via: prompt@0.2.14
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
228 Packages, Including:
@sailshq/lodash@3.10.4
accepts@1.3.8
anchor@1.4.1
ansi-regex@2.1.1
ansi-styles@2.2.1
ansi-styles@3.2.1
array-buffer-byte-length@1.0.1
array-flatten@1.1.1
array-flatten@2.1.1
async@0.2.10
async@2.0.1
async@2.5.0
available-typed-arrays@1.0.7
balanced-match@1.0.2
bluebird@3.2.1
body-parser@1.18.2
brace-expansion@1.1.11
bytes@3.0.0
call-bind@1.0.7
camelcase@1.2.1
captains-log@2.0.4
chalk@1.1.3
chalk@2.3.0
color-convert@1.9.3
color-name@1.1.3
colors@1.1.2
colors@1.4.0
commander@2.11.0
commander@2.8.1
common-js-file-extensions@1.0.2
compressible@2.0.18
compression@1.7.1
concat-map@0.0.1
connect@3.6.5
content-disposition@0.5.2
content-type@1.0.5
convert-to-ecmascript-compatible-varname@0.1.4
cookie-parser@1.4.3
cookie-signature@1.0.6
cookie@0.3.1
crc@3.4.4
cross-spawn@4.0.2
csrf@3.0.6
csurf@1.9.0
debug@2.6.9
debug@3.1.0
decamelize@1.2.0
deep-equal@2.2.3
deep-extend@0.4.2
deep-extend@0.6.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
26 Packages, Including:
fs.realpath@1.0.0
glob@7.1.2
glob@7.2.3
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.3
inherits@2.0.4
ini@1.3.8
isexe@2.0.0
lru-cache@4.1.5
lru-cache@6.0.0
minimatch@3.1.2
mute-stream@0.0.8
once@1.4.0
pseudomap@1.0.2
read@1.0.7
rimraf@2.7.1
semver@4.3.6
semver@7.5.2
setprototypeof@1.0.2
setprototypeof@1.0.3
setprototypeof@1.1.0
which@1.3.1
wrappy@1.0.2
yallist@2.1.2
yallist@4.0.0

N/A

N/A
5 Packages, Including:
colors@0.6.2
cycle@1.0.3
dot-access@1.0.0
prompt@0.2.14
utile@0.2.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
qs@6.5.1
sprintf@0.1.5

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
2 Packages, Including:
rc@1.2.2
rc@1.2.8

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
wordwrap@0.0.2
yargs@3.4.5

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
1 Packages, Including:
ejs@2.5.7

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
revalidator@0.1.8
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

44
All Dependencies CSV
β“˜ This is a list of sails 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@sailshq/lodash3.10.477.79 kBMIT
prod
async2.5.097.66 kBMIT
prod
1
captains-log2.0.415.2 kBMIT
prod
1
chalk2.3.09.06 kBMIT
prod
commander2.11.014.03 kBMIT
prod
common-js-file-extensions1.0.24.53 kBMIT
prod
compression1.7.17.53 kBMIT
prod
connect3.6.526.78 kBMIT
prod
cookie-parser1.4.33.73 kBMIT
prod
cookie-signature1.0.62.06 kBMIT
prod
cookie0.3.15.83 kBMIT
prod
csurf1.9.06.87 kBMIT
prod
ejs2.5.732.86 kBApache-2.0
prod
1
express-session1.15.620.99 kBMIT
prod
express4.16.252.78 kBMIT
prod
1
flaverr1.10.019.14 kBMIT
prod
glob7.1.215.25 kBISC
prod
i18n-20.6.310.6 kBMIT
prod
1
include-all4.0.311.02 kBMIT
prod
1
machine-as-action10.3.131.89 kBMIT
prod
machine15.2.31 BMIT
prod
machinepack-process2.0.28.18 kBMIT
prod
2
3
2
1
machinepack-redis1.3.020.23 kBMIT
prod
1
5
2
1
merge-defaults0.2.13.79 kBMIT
prod
1
2
2
1
merge-dictionaries1.0.06.68 kBMIT
prod
1
minimist0.0.106.05 kBMIT
prod
1
1
parley3.8.350.14 kBMIT
prod
parseurl1.3.23.7 kBMIT
prod
path-to-regexp1.5.37.51 kBMIT
prod
pluralize1.2.15.27 kBMIT
prod
prompt0.2.1421.82 kBUNKNOWN
prod
4
1
1
1
rc1.2.26.33 kB(BSD-2-Clause OR MIT OR Apache-2.0)
prod
1
1
router1.3.211.65 kBMIT
prod
rttc10.0.187.94 kBMIT
prod
sails-generate1.17.21.37 MBMIT
prod
2
sails-stringfile0.3.24.52 kBMIT
prod
1
2
2
1
semver4.3.644.41 kBISC
prod
1
serve-favicon2.4.56.57 kBMIT
prod
serve-static1.13.19.02 kBMIT
prod
skipper0.8.742.02 kBMIT
prod
2
6
3
1
sort-route-addresses0.0.15.75 kBMIT
prod
1
3
3
1
uid-safe2.1.53.93 kBMIT
prod
vary1.1.23.68 kBMIT
prod
whelk6.0.128.1 kBMIT
prod
2
2

Visualizations