Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 18, 2024 via pnpm
Package summary
Share
31
issues
7
critical severity
vulnerability
3
license
4
16
high severity
vulnerability
2
license
5
meta
9
3
moderate severity
vulnerability
2
meta
1
5
low severity
vulnerability
1
license
4
16
licenses
229
MIT
35
ISC
11
Apache-2.0
28
other licenses
BSD-3-Clause
8
N/A
4
BSD-2-Clause
3
Unlicense
3
+ 9 more
Package created
5 Mar 2015
Version published
6 Jul 2017
Maintainers
3
Total deps
303
Direct deps
6
License
Copyright (c) Sematext Group, Inc.

Issues

31

7 critical severity issues

critical
Recommendation: Upgrade to version 5.0.1 or later
via: spm-agent-os@1.30.17 & others
Recommendation: None
via: spm-agent-os@1.30.17
Recommendation: Upgrade to version 1.12.1 or later
via: spm-agent@1.31.20
Recommendation: Check the package code and files for license information
via: spm-agent@1.31.20
Recommendation: Check the package code and files for license information
via: spm-agent-os@1.30.17 & others
Recommendation: Check the package code and files for license information
via: spm-agent-os@1.30.17
Recommendation: Check the package code and files for license information
via: spm-agent@1.31.20
Collapse
Expand

16 high severity issues

high
Recommendation: None
via: spm-agent@1.31.20
Recommendation: Upgrade to version 3.0.5 or later
via: spm-agent-os@1.30.17
Recommendation: Validate that the package complies with your license policy
via: spm-agent-nodejs@1.30.9
Recommendation: Validate that the package complies with your license policy
via: spm-agent-os@1.30.17
Recommendation: Validate that the package complies with your license policy
via: spm-agent-os@1.30.17
Recommendation: Validate that the package complies with your license policy
via: spm-agent@1.31.20
Recommendation: Validate that the license expression complies with your license policy
via: spm-agent-os@1.30.17 & others
via: spm-agent-os@1.30.17
via: spm-agent-os@1.30.17
via: gc-stats@1.4.1
via: gc-stats@1.4.1
via: request@2.88.2 & others
via: measured@1.1.0
via: request@2.88.2 & others
via: request@2.88.2 & others
via: zip-zip-top@0.2.0
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Upgrade to version 4.1.3 or later
via: request@2.88.2 & others
Recommendation: None
via: request@2.88.2 & others
via: spm-agent-os@1.30.17 & others
Collapse
Expand

5 low severity issues

low
Recommendation: Upgrade to version 3.2.7 or later
via: spm-agent-os@1.30.17
Recommendation: Read and validate the license terms
via: spm-agent-nodejs@1.30.9
Recommendation: Read and validate the license terms
via: spm-agent-os@1.30.17
Recommendation: Read and validate the license terms
via: spm-agent-os@1.30.17
Recommendation: Read and validate the license terms
via: spm-agent@1.31.20
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
229 Packages, Including:
@types/caseless@0.12.5
@types/js-yaml@4.0.9
@types/node@18.19.31
@types/request@2.48.12
@types/tough-cookie@4.0.5
@types/ws@8.5.10
@yetzt/binary-search-tree@0.2.6
@yetzt/nedb@1.8.0
ajv@6.12.6
ansi-colors@3.2.3
ansi-regex@3.0.1
ansi-regex@4.1.1
ansi-styles@3.2.1
argparse@1.0.10
array-buffer-byte-length@1.0.1
array.prototype.reduce@1.0.7
arraybuffer.prototype.slice@1.0.3
asn1@0.2.6
assert-plus@1.0.0
async@0.2.10
async@2.6.4
async@3.2.5
asynckit@0.4.0
available-typed-arrays@1.0.7
aws4@1.12.0
balanced-match@1.0.2
binary-extensions@2.3.0
brace-expansion@1.1.11
braces@3.0.2
byline@5.0.0
call-bind@1.0.7
camelcase@5.3.1
chalk@2.4.2
chokidar@3.3.0
color-convert@1.9.3
color-name@1.1.3
colors@1.0.3
combined-stream@1.0.8
concat-map@0.0.1
core-util-is@1.0.2
core-util-is@1.0.3
dashdash@1.14.1
data-view-buffer@1.0.1
data-view-byte-length@1.0.1
data-view-byte-offset@1.0.0
debug@3.2.6
decamelize@1.2.0
deep-equal@0.1.2
deep-extend@0.6.0
define-data-property@1.1.4

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
35 Packages, Including:
anymatch@3.1.3
browser-stdout@1.3.1
chownr@2.0.0
cliui@5.0.0
fs-minipass@2.1.0
fs.realpath@1.0.0
get-caller-file@2.0.5
glob-parent@5.1.2
glob@7.1.3
har-schema@2.0.0
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
isexe@2.0.0
json-stringify-safe@5.0.1
lru-cache@4.1.5
lru-cache@6.0.0
minimatch@3.0.4
minipass@3.3.6
minipass@5.0.0
once@1.4.0
pseudomap@1.0.2
require-main-filename@2.0.0
semver@5.7.2
set-blocking@2.0.0
tar@6.2.1
which-module@2.0.1
which@1.3.1
which@2.0.2
wide-align@1.1.3
wrappy@1.0.2
y18n@4.0.3
yallist@2.1.2
yallist@4.0.0
yargs-parser@13.1.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
11 Packages, Including:
@kubernetes/client-node@0.18.1
aws-sign2@0.7.0
caseless@0.12.0
forever-agent@0.6.1
localforage@1.10.0
node-environment-flags@1.0.6
oauth-sign@0.9.0
request@2.88.2
spm-agent@1.31.20
spm-agent@2.2.5
tunnel-agent@0.6.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
8 Packages, Including:
bcrypt-pbkdf@1.0.2
diff@3.5.0
flat@2.0.2
flat@4.1.1
flat@5.0.2
qs@6.5.3
sprintf-js@1.0.3
tough-cookie@2.5.0

N/A

N/A
4 Packages, Including:
binary-search-tree@0.2.5
cycle@1.0.3
hexip@1.0.1
underscore@1.4.4

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
esprima@4.0.1
uri-js@4.4.1
webidl-conversions@3.0.1

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
3 Packages, Including:
gc-stats@1.4.1
stream-buffers@3.0.2
tweetnacl@0.14.5

Copyright (c) Sematext Group, Inc.

Invalid
Not OSI Approved
2 Packages, Including:
spm-agent-nodejs@1.30.9
spm-agent-os@1.30.17

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

Public Domain

Invalid
Not OSI Approved
1 Packages, Including:
jsonify@0.0.1

(MIT OR GPL-3.0-or-later)

Permissive
1 Packages, Including:
jszip@3.10.1

SEE LICENSE IN LICENSE

Invalid
Not OSI Approved
1 Packages, Including:
nedb@1.8.0

(MIT AND Zlib)

Permissive
1 Packages, Including:
pako@1.0.11

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
1 Packages, Including:
tslib@2.6.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

6
All Dependencies CSV
β“˜ This is a list of spm-agent-nodejs 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
gc-stats1.4.116.15 kBUnlicense
prod optional
2
measured1.1.07.89 kBMIT
prod
1
request2.88.257.83 kBApache-2.0
prod
3
2
spm-agent-os1.30.1710.19 kBCopyright (c) Sematext Group, Inc.
prod
4
9
3
3
spm-agent1.31.2017.14 kBApache-2.0
prod
5
6
3
1
zip-zip-top0.2.03.3 kBMIT
prod
1

Visualizations