Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 2, 2024 via pnpm

serverless 3.35.2

Serverless Framework - Build web, mobile and IoT applications with serverless architectures using AWS Lambda, Azure Functions, Google CloudFunctions & more
Package summary
Share
7
issues
6
high severity
meta
6
1
moderate severity
meta
1
11
licenses
374
MIT
76
Apache-2.0
65
ISC
19
other licenses
BSD-2-Clause
6
BSD-3-Clause
6
0BSD
2
Python-2.0
1
+ 4 more
Package created
9 Nov 2015
Version published
17 Sep 2023
Maintainers
4
Total deps
534
Direct deps
56
License
MIT

Issues

7

6 high severity issues

high
via: aws-sdk@2.1611.0
via: @serverless/dashboard-plugin@7.2.3 & others
via: aws-sdk@2.1611.0
via: @serverless/dashboard-plugin@7.2.3 & others
via: serverless@3.35.2
via: json-refs@3.0.15
Collapse
Expand

1 moderate severity issue

moderate
via: @serverless/dashboard-plugin@7.2.3 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
374 Packages, Including:
@kwsites/file-exists@1.1.1
@kwsites/promise-deferred@1.1.1
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@serverless/dashboard-plugin@7.2.3
@serverless/utils@6.15.0
@sindresorhus/is@4.6.0
@szmarczak/http-timer@4.0.6
@tokenizer/token@0.3.0
@types/cacheable-request@6.0.3
@types/http-cache-semantics@4.0.4
@types/keyv@3.1.4
@types/lodash@4.17.0
@types/node@20.12.8
@types/responselike@1.0.3
abort-controller@3.0.0
adm-zip@0.5.12
agent-base@6.0.2
ajv-formats@2.1.1
ajv@8.13.0
ansi-escapes@4.3.2
ansi-regex@5.0.1
ansi-styles@3.2.1
ansi-styles@4.3.0
archive-type@4.0.0
archiver-utils@2.1.0
archiver-utils@3.0.4
archiver@5.3.2
argparse@1.0.10
array-buffer-byte-length@1.0.1
array-union@2.1.0
arraybuffer.prototype.slice@1.0.3
asap@2.0.6
async@3.2.5
asynckit@0.4.0
available-typed-arrays@1.0.7
axios@1.6.8
balanced-match@1.0.2
base64-js@1.5.1
binary-extensions@2.3.0
bl@1.2.3
bl@4.1.0
bluebird@3.7.2
bowser@2.11.0
brace-expansion@1.1.11
brace-expansion@2.0.1
braces@3.0.2
buffer-alloc-unsafe@1.1.0
buffer-alloc@1.2.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
76 Packages, Including:
@aws-crypto/ie11-detection@3.0.0
@aws-crypto/sha256-browser@3.0.0
@aws-crypto/sha256-js@3.0.0
@aws-crypto/supports-web-crypto@3.0.0
@aws-crypto/util@3.0.0
@aws-sdk/client-cloudformation@3.567.0
@aws-sdk/client-sso-oidc@3.567.0
@aws-sdk/client-sso@3.567.0
@aws-sdk/client-sts@3.567.0
@aws-sdk/core@3.567.0
@aws-sdk/credential-provider-env@3.567.0
@aws-sdk/credential-provider-http@3.567.0
@aws-sdk/credential-provider-ini@3.567.0
@aws-sdk/credential-provider-node@3.567.0
@aws-sdk/credential-provider-process@3.567.0
@aws-sdk/credential-provider-sso@3.567.0
@aws-sdk/credential-provider-web-identity@3.567.0
@aws-sdk/middleware-host-header@3.567.0
@aws-sdk/middleware-logger@3.567.0
@aws-sdk/middleware-recursion-detection@3.567.0
@aws-sdk/middleware-user-agent@3.567.0
@aws-sdk/region-config-resolver@3.567.0
@aws-sdk/token-providers@3.567.0
@aws-sdk/types@3.567.0
@aws-sdk/util-endpoints@3.567.0
@aws-sdk/util-locate-window@3.567.0
@aws-sdk/util-user-agent-browser@3.567.0
@aws-sdk/util-user-agent-node@3.567.0
@aws-sdk/util-utf8-browser@3.259.0
@serverless/event-mocks@1.1.1
@smithy/abort-controller@2.2.0
@smithy/config-resolver@2.2.0
@smithy/core@1.4.2
@smithy/credential-provider-imds@2.3.0
@smithy/fetch-http-handler@2.5.0
@smithy/hash-node@2.2.0
@smithy/invalid-dependency@2.2.0
@smithy/is-array-buffer@2.2.0
@smithy/middleware-content-length@2.2.0
@smithy/middleware-endpoint@2.5.1
@smithy/middleware-retry@2.3.1
@smithy/middleware-serde@2.3.0
@smithy/middleware-stack@2.2.0
@smithy/node-config-provider@2.3.0
@smithy/node-http-handler@2.5.0
@smithy/property-provider@2.2.0
@smithy/protocol-http@3.3.0
@smithy/querystring-builder@2.2.0
@smithy/querystring-parser@2.2.0
@smithy/service-error-classification@2.1.5

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
65 Packages, Including:
2-thenable@1.0.0
@serverless/platform-client@4.5.1
anymatch@3.1.3
at-least-node@1.0.0
child-process-ext@2.1.1
child-process-ext@3.0.2
chownr@2.0.0
cli-color@2.0.4
cli-progress-footer@2.3.3
cli-sprintf-format@1.1.1
cli-width@3.0.0
d@1.0.2
deferred@0.7.11
dezalgo@1.0.4
duration@0.2.2
es5-ext@0.10.64
es6-set@0.1.6
es6-symbol@3.1.4
es6-weak-map@2.0.3
esniff@1.1.3
esniff@2.0.1
essentials@1.2.0
ext@1.7.0
fastq@1.17.1
find-requires@1.0.0
fs-minipass@2.1.0
fs.realpath@1.0.0
fs2@0.3.9
glob-parent@5.1.2
glob@7.2.3
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
isexe@2.0.0
log-node@8.0.3
log@6.3.1
lru-cache@6.0.0
memoizee@0.4.15
minimatch@3.1.2
minimatch@5.1.6
minipass@3.3.6
minipass@5.0.0
mute-stream@0.0.8
ncjsm@4.3.2
next-tick@1.1.0
npm-registry-utilities@1.0.0
once@1.4.0
process-utils@4.0.0
sax@1.2.1
semver@5.7.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
6 Packages, Including:
dotenv-expand@10.0.0
dotenv@16.4.5
esprima@4.0.1
http-cache-semantics@4.1.1
uri-js@4.4.1
webidl-conversions@3.0.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
6 Packages, Including:
filesize@10.1.1
flat@5.0.2
ieee754@1.1.13
ieee754@1.2.1
qs@6.12.1
sprintf-js@1.0.3

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

(MIT OR GPL-3.0-or-later)

Permissive
1 Packages, Including:
jszip@3.10.1

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
stream-buffers@3.0.2

(MIT OR CC0-1.0)

Public Domain
1 Packages, Including:
type-fest@0.21.3
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

56
All Dependencies CSV
β“˜ This is a list of serverless 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@serverless/dashboard-plugin7.2.31.66 MBMIT
prod
2
1
@serverless/platform-client4.5.1201 kBISC
prod
1
1
@serverless/utils6.15.049.95 kBMIT
prod
1
abort-controller3.0.017.14 kBMIT
prod
ajv-formats2.1.114.5 kBMIT
prod
ajv8.13.01006.09 kBMIT
prod peer
archiver5.3.213.02 kBMIT
prod
aws-sdk2.1611.091.17 MBApache-2.0
prod
2
bluebird3.7.2136.03 kBMIT
prod
cachedir2.4.02.57 kBMIT
prod
chalk4.1.211.31 kBMIT
prod
child-process-ext2.1.15.97 kBISC
prod
1
ci-info3.9.07.21 kBMIT
prod
cli-progress-footer2.3.329.68 kBISC
prod
1
d1.0.213.88 kBISC
prod
1
dayjs1.11.11650.17 kBMIT
prod
decompress4.2.13.2 kBMIT
prod
dotenv-expand10.0.05.49 kBBSD-2-Clause
prod
dotenv16.4.577.22 kBBSD-2-Clause
prod
essentials1.2.02.44 kBISC
prod
ext1.7.08.35 kBISC
prod
fastest-levenshtein1.0.165.96 kBMIT
prod
filesize10.1.151.79 kBBSD-3-Clause
prod
fs-extra10.1.016.52 kBMIT
prod
get-stdin8.0.02.18 kBMIT
prod
globby11.1.06.23 kBMIT
prod
graceful-fs4.2.119.57 kBISC
prod optional
https-proxy-agent5.0.18.21 kBMIT
prod
is-docker2.2.11.65 kBMIT
prod
js-yaml4.1.099.96 kBMIT
prod
json-colorizer2.2.23.2 kBMIT
prod
json-cycle1.5.04.2 kBMIT
prod
json-refs3.0.15752.13 kBMIT
prod
1
lodash4.17.21311.49 kBMIT
prod
memoizee0.4.1516.04 kBISC
prod
1
micromatch4.0.514.09 kBMIT
prod
node-fetch2.7.043.6 kBMIT
prod
npm-registry-utilities1.0.03.84 kBISC
prod
1
object-hash3.0.017.81 kBMIT
prod
open8.4.212.6 kBMIT
prod
path20.1.012.61 kBMIT
prod
process-utils4.0.07.29 kBISC
prod
1
promise-queue2.2.56.99 kBMIT
prod
require-from-string2.0.21.77 kBMIT
prod
semver7.6.026.57 kBISC
prod
signal-exit3.0.73.76 kBISC
prod
stream-buffers3.0.25.54 kBUnlicense
prod
strip-ansi6.0.11.99 kBMIT
prod
supports-color8.1.13.64 kBMIT
prod peer
tar6.2.1162.71 kBISC
prod
timers-ext0.1.75.3 kBISC
prod
1
type2.7.219.86 kBISC
prod
untildify4.0.01.63 kBMIT
prod
uuid9.0.122.94 kBMIT
prod
ws7.5.928.37 kBMIT
prod peer
yaml-ast-parser0.0.4384.9 kBApache-2.0
prod

Visualizations