Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 5, 2024 via pnpm

serverless-prune-plugin 1.5.1

Serverless plugin to delete old versions of deployed functions from AWS
Package summary
Share
37
issues
7
critical severity
vulnerability
1
license
6
17
high severity
vulnerability
3
license
4
meta
10
10
moderate severity
vulnerability
1
meta
9
3
low severity
license
3
15
licenses
504
MIT
79
ISC
18
BSD-3-Clause
41
other licenses
Apache-2.0
15
BSD-2-Clause
7
N/A
6
(MIT OR CC0-1.0)
3
+ 8 more
Package created
14 Jan 2017
Version published
5 Jul 2021
Maintainers
1
Total deps
642
Direct deps
2
License
MIT

Issues

37

7 critical severity issues

critical
Recommendation: Upgrade to version 3.16.0 or later
via: serverless@2.72.4
Recommendation: Check the package code and files for license information
via: serverless@2.72.4
Recommendation: Check the package code and files for license information
via: serverless@2.72.4
Recommendation: Check the package code and files for license information
via: serverless@2.72.4
Recommendation: Check the package code and files for license information
via: serverless@2.72.4
Recommendation: Check the package code and files for license information
via: serverless@2.72.4
Recommendation: Check the package code and files for license information
via: serverless@2.72.4
Collapse
Expand

17 high severity issues

high
Recommendation: Upgrade to version 3.3.0 or later
via: serverless@2.72.4
Recommendation: Upgrade to version 3.5.0 or later
via: serverless@2.72.4
Recommendation: Upgrade to version 3.15.0 or later
via: serverless@2.72.4
Recommendation: Validate that the package complies with your license policy
via: serverless@2.72.4
Recommendation: Validate that the package complies with your license policy
via: serverless@2.72.4
Recommendation: Validate that the package complies with your license policy
via: serverless@2.72.4
Recommendation: Validate that the license expression complies with your license policy
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 11.8.5 or later
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
via: serverless@2.72.4
Collapse
Expand

3 low severity issues

low
Recommendation: Read and validate the license terms
via: serverless@2.72.4
Recommendation: Read and validate the license terms
via: serverless@2.72.4
Recommendation: Read and validate the license terms
via: serverless@2.72.4
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
504 Packages, Including:
@colors/colors@1.6.0
@kwsites/file-exists@1.1.1
@kwsites/promise-deferred@1.1.1
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@serverless/cli@1.6.0
@serverless/components@3.18.2
@serverless/core@1.1.2
@serverless/dashboard-plugin@5.5.4
@serverless/utils-china@1.1.7
@serverless/utils@1.2.0
@serverless/utils@4.1.0
@serverless/utils@5.20.3
@sindresorhus/is@0.14.0
@sindresorhus/is@4.6.0
@szmarczak/http-timer@1.1.2
@szmarczak/http-timer@4.0.6
@tencent-sdk/capi@2.0.3
@tencent-sdk/common@1.0.0
@tokenizer/token@0.3.0
@types/cacheable-request@6.0.3
@types/http-cache-semantics@4.0.4
@types/keyv@3.1.4
@types/lodash@4.17.1
@types/long@4.0.2
@types/node@20.12.8
@types/responselike@1.0.3
@types/triple-beam@1.3.5
adm-zip@0.5.12
after@0.8.2
agent-base@6.0.2
ajv-keywords@3.5.2
ajv@6.12.6
ansi-escapes@3.2.0
ansi-escapes@4.3.2
ansi-regex@2.1.1
ansi-regex@3.0.1
ansi-regex@4.1.1
ansi-regex@5.0.1
ansi-styles@3.2.1
ansi-styles@4.3.0
archive-type@4.0.0
archiver-utils@2.1.0
archiver-utils@3.0.4
archiver@5.3.2
argparse@1.0.10
array-buffer-byte-length@1.0.1
array-union@2.1.0
arraybuffer.prototype.slice@1.0.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
79 Packages, Including:
2-thenable@1.0.0
@serverless/component-metrics@1.0.8
@serverless/platform-client-china@2.4.2
@serverless/platform-client@4.5.1
ansi-align@3.0.1
anymatch@3.1.3
aproba@1.2.0
are-we-there-yet@1.1.7
at-least-node@1.0.0
child-process-ext@2.1.1
chownr@1.1.4
chownr@2.0.0
cli-color@2.0.4
cli-progress-footer@2.3.3
cli-sprintf-format@1.1.1
cli-width@2.2.1
cli-width@3.0.0
console-control-strings@1.1.0
d@1.0.2
deferred@0.7.11
dezalgo@1.0.4
duration@0.2.2
es5-ext@0.10.64
es6-set@0.1.6
es6-symbol@3.1.4
es6-weak-map@2.0.3
esniff@1.1.3
esniff@2.0.1
essentials@1.2.0
ext@1.7.0
fastq@1.17.1
find-requires@1.0.0
fs-minipass@2.1.0
fs.realpath@1.0.0
fs2@0.3.9
gauge@2.7.4
glob-parent@5.1.2
glob@7.2.3
graceful-fs@4.2.11
has-unicode@2.0.1
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
inquirer-autocomplete-prompt@1.4.0
isexe@2.0.0
log-node@8.0.3
log@6.3.1
lru-cache@6.0.0
memoizee@0.4.15
minimatch@3.1.2

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
18 Packages, Including:
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
duplexer3@0.1.5
filesize@8.0.7
flat@5.0.2
ieee754@1.1.13
ieee754@1.2.1
protobufjs@6.11.4
qs@6.12.1
sprintf-js@1.0.3

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
15 Packages, Including:
@serverless/event-mocks@1.1.1
@serverless/template@1.1.4
aws-sdk@2.1613.0
crc-32@1.2.2
denque@1.5.1
detect-libc@1.0.3
jmespath@0.16.0
long@1.1.2
long@4.0.0
readdir-glob@1.1.3
rxjs@6.6.7
rxjs@7.8.1
tencent-serverless-http@1.3.2
tunnel-agent@0.6.0
yaml-ast-parser@0.0.43

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
7 Packages, Including:
dotenv-expand@5.1.0
dotenv@10.0.0
dotenv@8.6.0
esprima@4.0.1
http-cache-semantics@4.1.1
uri-js@4.4.1
webidl-conversions@3.0.1

N/A

N/A
6 Packages, Including:
buffers@0.1.1
component-bind@1.0.0
component-inherit@0.0.3
dot-qs@0.2.0
indexof@0.0.1
replaceall@0.1.6

(MIT OR CC0-1.0)

Public Domain
3 Packages, Including:
type-fest@0.20.2
type-fest@0.21.3
type-fest@1.4.0

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
chainsaw@0.1.0
traverse@0.3.9

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

(MIT OR WTFPL)

Permissive
1 Packages, Including:
expand-template@2.0.3

(MIT OR GPL-3.0-or-later)

Permissive
1 Packages, Including:
jszip@3.10.1

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
qrcode-terminal@0.12.0

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

2
All Dependencies CSV
β“˜ This is a list of serverless-prune-plugin 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
bluebird3.7.2136.03 kBMIT
prod
serverless2.72.41.19 MBMIT
prod peer
7
17
10
3

Visualizations