Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 23, 2024 via pnpm

salesforce-alm 54.3.2

This package contains tools, and APIs, for an improved salesforce.com developer experience.
Package summary
Share
25
issues
2
critical severity
license
2
11
high severity
vulnerability
2
license
2
meta
7
10
moderate severity
vulnerability
8
meta
2
2
low severity
license
2
14
licenses
328
MIT
41
ISC
18
BSD-3-Clause
35
other licenses
Apache-2.0
18
BSD-2-Clause
3
0BSD
3
Unlicense
2
+ 7 more
Package created
7 Dec 2016
Version published
10 May 2022
Maintainers
3
Total deps
422
Direct deps
34
License
BSD-3-Clause

Issues

25

2 critical severity issues

critical
Recommendation: Check the package code and files for license information
via: @salesforce/source-deploy-retrieve@5.15.0 & others
Recommendation: Check the package code and files for license information
via: @salesforce/command@4.2.2 & others
Collapse
Expand

11 high severity issues

high
Recommendation: Upgrade to version 4.1.1 or later
via: heroku-cli-util@8.0.12
Recommendation: None
via: @salesforce/command@4.2.2
Recommendation: Validate that the package complies with your license policy
via: @salesforce/source-deploy-retrieve@5.15.0 & others
Recommendation: Validate that the package complies with your license policy
via: @salesforce/source-deploy-retrieve@5.15.0 & others
via: @salesforce/command@4.2.2 & others
via: @salesforce/command@4.2.2
via: cli-ux@5.6.7
via: @salesforce/command@4.2.2 & others
via: @salesforce/command@4.2.2 & others
via: @salesforce/command@4.2.2 & others
via: @salesforce/command@4.2.2 & others
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 11.8.5 or later
via: heroku-cli-util@8.0.12
Recommendation: Upgrade to version 9.0.0 or later
via: @salesforce/command@4.2.2 & others
Recommendation: Upgrade to version 9.0.0 or later
via: @salesforce/command@4.2.2 & others
Recommendation: Upgrade to version 9.0.0 or later
via: @salesforce/command@4.2.2 & others
Recommendation: Upgrade to version 4.1.2 or later
via: @salesforce/source-deploy-retrieve@5.15.0 & others
Recommendation: Upgrade to version 4.1.3 or later
via: @salesforce/command@4.2.2 & others
Recommendation: Upgrade to version 0.5.0 or later
via: xml2js@0.4.19
Recommendation: None
via: @salesforce/command@4.2.2 & others
via: @salesforce/command@4.2.2 & others
via: salesforce-alm@54.3.2
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: @salesforce/source-deploy-retrieve@5.15.0 & others
Recommendation: Read and validate the license terms
via: @salesforce/source-deploy-retrieve@5.15.0 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
328 Packages, Including:
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@oclif/command@1.8.36
@oclif/config@1.18.16
@oclif/config@1.18.17
@oclif/errors@1.3.6
@oclif/help@1.0.15
@oclif/parser@3.8.17
@oclif/parser@3.8.6
@oclif/plugin-help@2.2.3
@oclif/screen@1.0.4
@oclif/test@1.2.9
@salesforce/bunyan@2.0.0
@sindresorhus/is@0.7.0
@types/chai@4.3.14
@types/graceful-fs@4.1.9
@types/jsforce@1.11.5
@types/keyv@3.1.4
@types/lodash@4.17.0
@types/mkdirp@1.0.2
@types/node@20.12.7
@types/responselike@1.0.3
@types/sinon@17.0.3
@types/sinonjs__fake-timers@8.1.5
adm-zip@0.5.12
ajv@6.12.6
ajv@8.12.0
ansi-escapes@3.2.0
ansi-escapes@4.3.2
ansi-regex@3.0.1
ansi-regex@4.1.1
ansi-regex@5.0.1
ansi-styles@3.2.1
ansi-styles@4.3.0
ansicolors@0.3.2
archiver-utils@2.1.0
archiver-utils@3.0.4
archiver@5.3.2
argparse@1.0.10
array-union@2.1.0
asap@2.0.6
asn1@0.2.6
assert-plus@1.0.0
async-lock@1.4.1
async@3.2.5
asynckit@0.4.0
aws4@1.12.0
balanced-match@1.0.2
base64-js@1.5.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
41 Packages, Including:
@heroku-cli/color@1.1.16
@oclif/linewrap@1.0.0
@salesforce/schemas@1.7.0
base64-url@2.3.3
cliui@6.0.0
fastq@1.17.1
fs.realpath@1.0.0
fstream@1.0.12
get-caller-file@2.0.5
glob-parent@5.1.2
glob@6.0.4
glob@7.2.3
graceful-fs@4.2.11
har-schema@2.0.0
heroku-cli-util@8.0.12
inflight@1.0.6
inherits@2.0.4
isexe@2.0.0
json-stringify-safe@5.0.1
listenercount@1.0.1
lru-cache@6.0.0
minimatch@3.0.5
minimatch@3.1.2
minimatch@5.1.6
netrc-parser@3.1.6
once@1.4.0
require-main-filename@2.0.0
rimraf@2.4.5
rimraf@2.7.1
sax@1.3.0
semver@5.7.2
semver@7.6.0
set-blocking@2.0.0
signal-exit@3.0.7
which-module@2.0.1
which@1.3.1
which@2.0.2
wrappy@1.0.2
y18n@4.0.3
yallist@4.0.0
yargs-parser@18.1.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
18 Packages, Including:
@salesforce/command@4.2.2
@salesforce/core@2.37.1
@salesforce/kit@1.9.2
@salesforce/source-deploy-retrieve@5.15.0
@salesforce/source-tracking@1.5.0
@salesforce/ts-types@1.7.3
bcrypt-pbkdf@1.0.2
buffer-equal-constant-time@1.0.1
csv-stringify@1.1.2
duplexer2@0.1.4
duplexer3@0.1.5
ieee754@1.2.1
qs@6.5.3
salesforce-alm@54.3.2
shelljs@0.8.5
sprintf-js@1.0.3
tough-cookie@2.5.0
tough-cookie@4.1.3

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
18 Packages, Including:
aws-sign2@0.7.0
caseless@0.12.0
clean-git-ref@2.0.1
crc-32@1.2.2
ecdsa-sig-formatter@1.0.11
faye-websocket@0.11.4
faye@1.4.0
forever-agent@0.6.1
js2xmlparser@3.0.0
js2xmlparser@4.0.2
oauth-sign@0.9.0
readdir-glob@1.1.3
request@2.88.2
tunnel-agent@0.6.0
websocket-driver@0.7.4
websocket-extensions@0.1.4
xmlcreate@1.0.2
xmlcreate@2.0.4

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
esprima@4.0.1
http-cache-semantics@3.8.1
uri-js@4.4.1

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
3 Packages, Including:
password-prompt@1.1.3
tslib@1.14.1
tslib@2.6.2

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
2 Packages, Including:
big-integer@1.6.52
tweetnacl@0.14.5

N/A

N/A
2 Packages, Including:
buffers@0.1.1
dtrace-provider@0.6.0

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
chainsaw@0.1.0
traverse@0.3.9

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

(MIT AND BSD-3-Clause)

Permissive
1 Packages, Including:
sha.js@2.4.11

(MIT OR CC0-1.0)

Public Domain
1 Packages, Including:
type-fest@0.21.3

(LGPL-2.0 or MIT)

Permissive
1 Packages, Including:
xmldom-sfdx-encoding@0.1.30
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

34
All Dependencies CSV
β“˜ This is a list of salesforce-alm 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@oclif/config1.18.1714.26 kBMIT
prod
@oclif/errors1.3.65.96 kBMIT
prod
@salesforce/command4.2.229.34 kBBSD-3-Clause
prod
1
7
6
@salesforce/core2.37.1177.6 kBBSD-3-Clause
prod
1
4
6
@salesforce/kit1.9.229.94 kBBSD-3-Clause
prod
@salesforce/source-deploy-retrieve5.15.0159.95 kBBSD-3-Clause
prod
2
6
7
2
@salesforce/source-tracking1.5.034.5 kBBSD-3-Clause
prod
2
6
7
2
@salesforce/ts-types1.7.324.61 kBBSD-3-Clause
prod
adm-zip0.5.12101.27 kBMIT
prod
ansi-styles3.2.13.72 kBMIT
prod
archiver5.3.213.02 kBMIT
prod
bluebird3.7.2136.03 kBMIT
prod
bunyan-sfdx-no-dtrace1.8.2266.12 kBMIT
prod
1
1
chalk2.4.29.63 kBMIT
prod
cli-ux5.6.725.18 kBMIT
prod
2
debug3.2.716.48 kBMIT
prod
fast-xml-parser3.21.121.04 kBMIT
prod
1
fs-extra4.0.334.69 kBMIT
prod
glob7.2.315.08 kBISC
prod
heroku-cli-util8.0.1223.66 kBISC
prod
1
1
js2xmlparser3.0.013.32 kBApache-2.0
prod
jsforce1.11.12.04 MBMIT
prod
3
3
klaw2.1.14.86 kBMIT
prod
lodash4.17.21311.49 kBMIT
prod
mime1.6.015.32 kBMIT
prod
mkdirp0.5.62.95 kBMIT
prod optional
moment2.30.1698.76 kBMIT
prod optional
optional-js1.3.114.75 kBMIT
prod
replace1.2.27.16 kBMIT
prod
request2.88.257.83 kBApache-2.0
prod
3
2
strip-ansi5.2.02.07 kBMIT
prod
ts-retry-promise0.6.28.23 kBMIT
prod
xml2js0.4.1912.08 kBMIT
prod
1
xmldom-sfdx-encoding0.1.3020.94 kB(LGPL-2.0 or MIT)
prod

Visualizations