Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 12, 2024 via pnpm

saml-idp 1.2.1

Test Identity Provider (IdP) for SAML 2.0 Web Browser SSO Profile
Package summary
Share
8
issues
1
critical severity
vulnerability
1
3
high severity
license
1
meta
2
2
moderate severity
vulnerability
2
2
low severity
vulnerability
1
license
1
7
licenses
107
MIT
9
ISC
3
BSD-3-Clause
4
other licenses
Apache2
1
BSD-2-Clause
1
(MIT OR Apache-2.0)
1
(LGPL-2.0 OR MIT)
1
Package created
18 Apr 2016
Version published
2 Jun 2020
Maintainers
1
Total deps
123
Direct deps
11
License
MIT

Issues

8

3 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: hbs@4.2.0
via: debug@4.1.1
via: xmldom@0.3.0
Collapse
Expand

2 moderate severity issues

moderate
Recommendation: Upgrade to version 0.5.0 or later
via: xmldom@0.3.0
Recommendation: None
via: xmldom@0.3.0
Collapse
Expand

2 low severity issues

low
Recommendation: Upgrade to version 4.3.1 or later
via: debug@4.1.1
Recommendation: Read and validate the license terms
via: hbs@4.2.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
107 Packages, Including:
accepts@1.3.8
ansi-regex@5.0.1
ansi-styles@4.3.0
array-flatten@1.1.1
basic-auth@2.0.1
body-parser@1.19.2
body-parser@1.20.2
bytes@3.1.2
call-bind@1.0.7
camelcase@5.3.1
chalk@4.1.2
color-convert@2.0.1
color-name@1.1.4
content-disposition@0.5.4
content-type@1.0.5
cookie-signature@1.0.6
cookie-signature@1.0.7
cookie@0.6.0
debug@2.6.9
debug@4.1.1
decamelize@1.2.0
define-data-property@1.1.4
depd@1.1.2
depd@2.0.0
destroy@1.2.0
ee-first@1.1.1
emoji-regex@8.0.0
encodeurl@1.0.2
es-define-property@1.0.0
es-errors@1.3.0
escape-html@1.0.3
etag@1.8.1
express-session@1.18.0
express@4.19.2
extend@3.0.2
finalhandler@1.2.0
find-up@4.1.0
forwarded@0.2.0
fresh@0.5.2
function-bind@1.1.2
get-intrinsic@1.2.4
gopd@1.0.1
handlebars@4.7.7
has-flag@4.0.0
has-property-descriptors@1.0.2
has-proto@1.0.3
has-symbols@1.0.3
hasown@2.0.2
hbs@4.2.0
http-errors@1.8.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
cliui@6.0.0
get-caller-file@2.0.5
inherits@2.0.4
require-main-filename@2.0.0
set-blocking@2.0.0
setprototypeof@1.2.0
which-module@2.0.1
y18n@4.0.3
yargs-parser@18.1.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
qs@6.11.0
qs@6.9.7
source-map@0.6.1

Apache2

Invalid
Not OSI Approved
1 Packages, Including:
foreachasync@3.0.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
uglify-js@3.17.4

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
walk@2.3.15

(LGPL-2.0 OR MIT)

Permissive
1 Packages, Including:
xmldom@0.3.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

11
All Dependencies CSV
β“˜ This is a list of saml-idp 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
body-parser1.19.213.61 kBMIT
prod
chalk4.1.211.31 kBMIT
prod
debug4.1.121.26 kBMIT
prod
1
1
express-session1.18.022.25 kBMIT
prod
express4.19.2209.73 kBMIT
prod
extend3.0.27.09 kBMIT
prod
hbs4.2.07.3 kBMIT
prod
1
1
morgan1.10.09.37 kBMIT
prod
xml-formatter2.6.16.25 kBMIT
prod
xmldom0.3.021.26 kB(LGPL-2.0 OR MIT)
prod
1
1
2
yargs15.4.154.97 kBMIT
prod

Visualizations