Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 1, 2024 via pnpm

superstatic 2.2.1

Superstatic: a static file server for fancy apps
Package summary
Share
63
issues
7
critical severity
vulnerability
1
license
6
39
high severity
vulnerability
16
license
9
meta
14
6
moderate severity
vulnerability
6
11
low severity
vulnerability
3
license
8
10
licenses
377
MIT
29
ISC
7
BSD
16
other licenses
N/A
6
BSD-3-Clause
4
Apache-2.0
2
(MIT OR Apache-2.0)
1
+ 3 more
Package created
24 Oct 2013
Version published
19 Jun 2015
Maintainers
3
Total deps
429
Direct deps
53
License
MIT

Issues

63

7 critical severity issues

critical
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@3.10.1 & others
Recommendation: Check the package code and files for license information
via: tiny-lr@0.1.7
Recommendation: Check the package code and files for license information
via: tiny-lr@0.1.7
Recommendation: Check the package code and files for license information
via: install@0.1.8
Recommendation: Check the package code and files for license information
via: tiny-lr@0.1.7
Recommendation: Check the package code and files for license information
via: finalhandler@0.4.1 & others
Recommendation: Check the package code and files for license information
via: jfig@1.2.0 & others
Collapse
Expand

39 high severity issues

high
Recommendation: Upgrade to version 5.0.2 or later
via: superstatic@2.2.1
Recommendation: Upgrade to version 5.0.2 or later
via: superstatic@2.2.1
Recommendation: Upgrade to version 6.0.4 or later
via: connect-query@0.2.0 & others
Recommendation: Upgrade to version 1.2.1 or later
via: redirects@1.1.1
Recommendation: Upgrade to version 0.5.2 or later
via: send@0.13.2
Recommendation: Upgrade to version 3.0.2 or later
via: glob@5.0.15 & others
Recommendation: Upgrade to version 1.4.1 or later
via: send@0.13.2
Recommendation: Upgrade to version 2.6.9 or later
via: finalhandler@0.4.1 & others
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@3.10.1 & others
Recommendation: Upgrade to version 0.7.1 or later
via: tiny-lr@0.1.7
Recommendation: Upgrade to version 5.1.2 or later
via: chokidar@1.7.0
Recommendation: Upgrade to version 4.17.19 or later
via: lodash@3.10.1 & others
Recommendation: Upgrade to version 6.2.4 or later
via: connect-query@0.2.0 & others
Recommendation: Upgrade to version 2.1.1 or later
via: redirects@1.1.1
Recommendation: Upgrade to version 3.0.5 or later
via: glob@5.0.15 & others
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@3.10.1 & others
Recommendation: Validate that the package complies with your license policy
via: caseless@0.10.0
Recommendation: Validate that the package complies with your license policy
via: update-notifier@0.3.2
Recommendation: Validate that the package complies with your license policy
via: connect-query@0.2.0
Recommendation: Validate that the package complies with your license policy
via: tiny-lr@0.1.7
Recommendation: Validate that the package complies with your license policy
via: tiny-lr@0.1.7
Recommendation: Validate that the package complies with your license policy
via: cache-control@1.0.3 & others
Recommendation: Validate that the package complies with your license policy
via: update-notifier@0.3.2
Recommendation: Validate that the license expression complies with your license policy
via: update-notifier@0.3.2
Recommendation: Validate that the package complies with your license policy
via: redirects@1.1.1
via: chokidar@1.7.0
via: chokidar@1.7.0
via: chokidar@1.7.0
via: jfig@1.2.0
via: glob@5.0.15 & others
via: fs-extra@0.20.1 & others
via: npmconf@2.1.3
via: chokidar@1.7.0
via: redirects@1.1.1
via: chokidar@1.7.0
via: chokidar@1.7.0
via: cross-spawn@0.4.1
via: chokidar@1.7.0
via: update-notifier@0.3.2
Collapse
Expand

6 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@3.10.1 & others
Recommendation: Upgrade to version 11.8.5 or later
via: update-notifier@0.3.2
Recommendation: Upgrade to version 2.6.9 or later
via: finalhandler@0.4.1 & others
Recommendation: Upgrade to version 2.0.0 or later
via: finalhandler@0.4.1 & others
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@3.10.1 & others
Recommendation: Upgrade to version 5.7.2 or later
via: npmconf@2.1.3
Collapse
Expand

11 low severity issues

low
Recommendation: Upgrade to version 2.3.1 or later
via: chokidar@1.7.0
Recommendation: Upgrade to version 4.17.5 or later
via: lodash@3.10.1 & others
Recommendation: Upgrade to version 2.3.1 or later
via: chokidar@1.7.0
Recommendation: Read and validate the license terms
via: caseless@0.10.0
Recommendation: Read and validate the license terms
via: update-notifier@0.3.2
Recommendation: Read and validate the license terms
via: connect-query@0.2.0
Recommendation: Read and validate the license terms
via: tiny-lr@0.1.7
Recommendation: Read and validate the license terms
via: tiny-lr@0.1.7
Recommendation: Read and validate the license terms
via: cache-control@1.0.3 & others
Recommendation: Read and validate the license terms
via: update-notifier@0.3.2
Recommendation: Read and validate the license terms
via: redirects@1.1.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
377 Packages, Including:
@types/keyv@3.1.4
@types/node@20.11.24
@types/responselike@1.0.3
accepts@1.3.8
amp-is-object@1.0.1
amp-is-string@1.0.1
ansi-regex@2.1.1
ansi-styles@0.2.0
ansi-styles@2.2.1
argparse@1.0.10
arr-diff@2.0.0
arr-diff@4.0.0
arr-flatten@1.1.0
arr-union@3.1.0
array-flatten@1.1.1
array-flatten@3.0.0
array-unique@0.2.1
array-unique@0.3.2
as-array@1.0.0
as-array@2.0.0
assign-symbols@1.0.0
async-each@1.0.6
async@0.9.2
async@1.5.2
balanced-match@1.0.2
base@0.11.2
basic-auth-connect@1.0.0
basic-auth@2.0.1
binary-extensions@1.13.1
bindings@1.5.0
body-parser@1.20.2
body-parser@1.8.4
booly@1.0.2
brace-expansion@1.1.11
braces@1.8.5
braces@2.3.2
buffer-from@1.1.2
bundles@2.0.0
bytes@3.0.0
bytes@3.1.2
cache-base@1.0.1
cache-control@1.0.3
cache-header@1.0.3
call-bind@1.0.7
caller-path@0.1.0
callsites@0.2.0
chalk@0.3.0
chalk@1.1.3
chokidar@1.7.0
class-utils@0.3.6

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
29 Packages, Including:
abbrev@1.1.1
anymatch@1.3.2
char-spinner@1.0.1
fs.realpath@1.0.0
glob-parent@2.0.0
glob@5.0.15
glob@7.2.3
graceful-fs@3.0.12
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
lru-cache@2.7.3
minimatch@2.0.10
minimatch@3.1.2
natives@1.1.6
nopt@3.0.6
npmconf@2.1.3
once@1.3.3
once@1.4.0
osenv@0.1.5
proto-list@1.2.4
remove-trailing-separator@1.1.0
rimraf@2.7.1
semver@4.3.6
semver@5.7.2
setprototypeof@1.2.0
uid-number@0.0.5
wrappy@1.0.2

BSD

Invalid
Not OSI Approved
7 Packages, Including:
caseless@0.10.0
configstore@0.3.2
qs@1.1.0
qs@2.2.4
qs@2.2.5
regular@0.1.6
update-notifier@0.3.2

N/A

N/A
6 Packages, Including:
bytes@1.0.0
debug@2.0.0
install@0.1.8
ms@0.6.2
ms@0.7.1
valid-url@1.0.9

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
4 Packages, Including:
qs@3.1.0
qs@6.11.0
source-map@0.5.7
sprintf-js@1.0.3

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
websocket-driver@0.7.4
websocket-extensions@0.1.4

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
esprima@4.0.1

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
reverend@0.2.0
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

53
All Dependencies CSV
β“˜ This is a list of superstatic 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
as-array1.0.01.32 kBMIT
prod
async1.5.238.01 kBMIT
prod
basic-auth-connect1.0.02.77 kBMIT
prod
booly1.0.21.97 kBMIT
prod
bundles2.0.03.08 kBMIT
prod
cache-control1.0.32.54 kBMIT
prod
1
1
cache-header1.0.32.3 kBMIT
prod
1
1
caseless0.10.01.76 kBBSD
prod
1
1
chalk1.1.35.11 kBMIT
prod
char-spinner1.0.12.21 kBISC
prod
chokidar1.7.022.33 kBMIT
prod
8
2
clear-require1.0.11.03 kBMIT
prod
compare-semver1.1.01.45 kBMIT
prod
compression1.7.47.64 kBMIT
prod
connect-livereload0.5.44.87 kBMIT
prod
connect-query0.2.01.35 kBMIT
prod
3
1
connect3.7.026.84 kBMIT
prod
cross-spawn0.4.13.75 kBMIT
prod
1
destroy1.2.03.3 kBMIT
prod
etag1.8.14.28 kBMIT
prod
express4.18.3209.05 kBMIT
prod
fast-url-parser1.1.39.67 kBMIT
prod
finalhandler0.4.13.93 kBMIT
prod
1
1
2
firstkey0.1.02.22 kBMIT
prod
flatten-to-object1.0.01.04 kBMIT
prod
fs-extra0.20.114.87 kBMIT
prod
1
glob-slasher1.0.12.59 kBMIT
prod
glob5.0.1514.45 kBISC
prod
3
globject1.0.21.48 kBMIT
prod
home-dir1.0.01.4 kBMIT
prod
install0.1.811.41 kBUNKNOWN
prod
1
jfig1.2.02.92 kBMIT
prod
1
1
join-path1.1.12.16 kBMIT
prod
1
lodash3.10.1169.48 kBMIT
prod
1
3
2
1
mime-types2.1.355.46 kBMIT
prod
minimatch2.0.1013.61 kBISC
prod
3
morgan1.10.09.37 kBMIT
prod
nash2.0.415.76 kBMIT
prod
1
3
2
1
npmconf2.1.314.25 kBISC
prod
1
1
on-finished2.4.14.93 kBMIT
prod
on-headers1.0.23.15 kBMIT
prod
pretty-print1.1.01.94 kBMIT
prod
1
2
2
1
qs3.1.012.8 kBBSD-3-Clause
prod
2
redirects1.1.12.8 kBMIT
prod
4
1
router1.3.812.9 kBMIT
prod
send0.13.210.91 kBMIT
prod
1
3
2
serve-favicon2.5.06.67 kBMIT
prod
set-headers1.0.02.35 kBMIT
prod
string-length1.0.11.57 kBMIT
prod
through22.0.53.96 kBMIT
prod
tiny-lr0.1.710.5 kBMIT
prod
3
6
2
2
try-require1.2.12.07 kBMIT
prod
update-notifier0.3.23.88 kBBSD
prod
5
1
2

Visualizations