Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 3, 2024 via pnpm

salesforce-alm 54.8.5

This package contains tools, and APIs, for an improved salesforce.com developer experience.
Package summary
Share
14
issues
4
critical severity
vulnerability
2
license
2
5
high severity
license
2
meta
3
3
moderate severity
vulnerability
2
meta
1
2
low severity
license
2
12
licenses
335
MIT
33
ISC
18
Apache-2.0
35
other licenses
BSD-3-Clause
17
BSD-2-Clause
7
0BSD
3
N/A
2
+ 5 more
Package created
7 Dec 2016
Version published
4 Jan 2023
Maintainers
3
Total deps
421
Direct deps
29
License
BSD-3-Clause

Issues

14

4 critical severity issues

critical
Recommendation: None
via: @salesforce/source-deploy-retrieve@7.15.1 & others
Recommendation: None
via: @salesforce/source-deploy-retrieve@7.15.1 & others
Recommendation: Check the package code and files for license information
via: @salesforce/source-deploy-retrieve@7.15.1 & others
Recommendation: Check the package code and files for license information
via: @salesforce/bunyan@2.0.0 & others
Collapse
Expand

5 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: @salesforce/source-deploy-retrieve@7.15.1 & others
Recommendation: Validate that the package complies with your license policy
via: @salesforce/source-deploy-retrieve@7.15.1 & others
via: @salesforce/command@5.3.9 & others
via: @salesforce/command@5.3.9 & others
via: @salesforce/bunyan@2.0.0 & others
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Upgrade to version 4.1.2 or later
via: fast-xml-parser@3.21.1
Recommendation: Upgrade to version 0.5.0 or later
via: xml2js@0.4.19
via: salesforce-alm@54.8.5
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: @salesforce/source-deploy-retrieve@7.15.1 & others
Recommendation: Read and validate the license terms
via: @salesforce/source-deploy-retrieve@7.15.1 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
335 Packages, Including:
@babel/runtime-corejs3@7.24.5
@babel/runtime@7.24.5
@cspotcode/source-map-support@0.8.1
@jridgewell/resolve-uri@3.1.2
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.9
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@oclif/core@1.26.2
@oclif/core@2.16.0
@oclif/screen@3.0.8
@oclif/test@2.5.6
@salesforce/bunyan@2.0.0
@sindresorhus/is@4.6.0
@szmarczak/http-timer@4.0.6
@tootallnate/once@1.1.2
@tsconfig/node10@1.0.11
@tsconfig/node12@1.0.11
@tsconfig/node14@1.0.3
@tsconfig/node16@1.0.4
@types/cacheable-request@6.0.3
@types/chai@4.3.15
@types/cli-progress@3.11.5
@types/http-cache-semantics@4.0.4
@types/keyv@3.1.4
@types/lodash@4.17.0
@types/node@12.20.55
@types/node@20.12.8
@types/responselike@1.0.3
@types/semver@7.5.8
@types/sinon@17.0.3
@types/sinonjs__fake-timers@8.1.5
@xmldom/xmldom@0.8.10
abort-controller@3.0.0
acorn-walk@8.3.2
acorn@8.11.3
adm-zip@0.5.12
agent-base@6.0.2
ajv@8.13.0
ansi-escapes@4.3.2
ansi-regex@4.1.1
ansi-regex@5.0.1
ansi-styles@3.2.1
ansi-styles@4.3.0
ansicolors@0.3.2
archiver-utils@2.1.0
archiver-utils@3.0.4
archiver@5.3.2
arg@4.1.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
33 Packages, Including:
@oclif/linewrap@1.0.0
@salesforce/schemas@1.7.0
at-least-node@1.0.0
cli-width@3.0.0
fastq@1.17.1
fs.realpath@1.0.0
fstream@1.0.12
glob-parent@5.1.2
glob@6.0.4
glob@7.2.3
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
isexe@2.0.0
json-stringify-safe@5.0.1
listenercount@1.0.1
lru-cache@5.1.1
lru-cache@6.0.0
make-error@1.3.6
minimatch@3.1.2
minimatch@5.1.6
mute-stream@0.0.8
once@1.4.0
rimraf@2.4.5
rimraf@2.7.1
sax@1.3.0
semver@7.6.0
setprototypeof@1.2.0
signal-exit@3.0.7
which@2.0.2
wrappy@1.0.2
yallist@3.1.1
yallist@4.0.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
18 Packages, Including:
clean-git-ref@2.0.1
crc-32@1.2.2
ecdsa-sig-formatter@1.0.11
ejs@3.1.10
faye-websocket@0.11.4
faye@1.4.0
filelist@1.0.4
jake@10.8.7
js2xmlparser@3.0.0
js2xmlparser@4.0.2
readdir-glob@1.1.3
rxjs@6.6.7
tunnel-agent@0.6.0
typescript@5.4.5
websocket-driver@0.7.4
websocket-extensions@0.1.4
xmlcreate@1.0.2
xmlcreate@2.0.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
17 Packages, Including:
@salesforce/command@5.3.9
@salesforce/core@3.36.2
@salesforce/kit@1.9.2
@salesforce/source-deploy-retrieve@7.15.1
@salesforce/source-deploy-retrieve@8.6.0
@salesforce/source-tracking@2.2.28
@salesforce/ts-types@1.7.3
buffer-equal-constant-time@1.0.1
diff@4.0.2
duplexer2@0.1.4
ieee754@1.2.1
salesforce-alm@54.8.5
shelljs@0.8.5
source-map@0.6.1
sprintf-js@1.0.3
sprintf-js@1.1.3
tough-cookie@4.1.4

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
7 Packages, Including:
escodegen@1.14.3
esprima@4.0.1
estraverse@4.3.0
esutils@2.0.3
http-cache-semantics@4.1.1
uri-js@4.4.1
webidl-conversions@3.0.1

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
3 Packages, Including:
password-prompt@1.1.3
tslib@1.14.1
tslib@2.6.2

N/A

N/A
2 Packages, Including:
buffers@0.1.1
dtrace-provider@0.6.0

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
chainsaw@0.1.0
traverse@0.3.9

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
big-integer@1.6.52

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

(MIT AND BSD-3-Clause)

Permissive
1 Packages, Including:
sha.js@2.4.11

(MIT OR CC0-1.0)

Public Domain
1 Packages, Including:
type-fest@0.21.3
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

29
All Dependencies CSV
β“˜ This is a list of salesforce-alm 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@oclif/core1.26.273.29 kBMIT
prod
@salesforce/bunyan2.0.058.72 kBMIT
prod
1
1
@salesforce/command5.3.947.48 kBBSD-3-Clause
prod
1
3
@salesforce/core3.36.2232.33 kBBSD-3-Clause
prod
1
3
@salesforce/kit1.9.229.94 kBBSD-3-Clause
prod
@salesforce/source-deploy-retrieve7.15.1142.88 kBBSD-3-Clause
prod
4
5
2
@salesforce/source-tracking2.2.2852.89 kBBSD-3-Clause
prod
4
5
2
@salesforce/ts-types1.7.324.61 kBBSD-3-Clause
prod
@xmldom/xmldom0.8.1050.64 kBMIT
prod
adm-zip0.5.12101.27 kBMIT
prod
ansi-styles3.2.13.72 kBMIT
prod
archiver5.3.213.02 kBMIT
prod
bluebird3.7.2136.03 kBMIT
prod
chalk2.4.29.63 kBMIT
prod
debug3.2.716.48 kBMIT
prod
fast-xml-parser3.21.121.04 kBMIT
prod
1
fs-extra4.0.334.69 kBMIT
prod
glob7.2.315.08 kBISC
prod
js2xmlparser3.0.013.32 kBApache-2.0
prod
jsforce2.0.0-beta.297.52 MBMIT
prod
2
klaw2.1.14.86 kBMIT
prod
lodash4.17.21311.49 kBMIT
prod
mime1.6.015.32 kBMIT
prod
mkdirp0.5.62.95 kBMIT
prod optional
moment2.30.1698.76 kBMIT
prod
optional-js1.3.114.75 kBMIT
prod
strip-ansi5.2.02.07 kBMIT
prod
ts-retry-promise0.6.28.23 kBMIT
prod
xml2js0.4.1912.08 kBMIT
prod
1

Visualizations