Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 4, 2024 via pnpm

superstatic 4.2.1

A static file server for fancy apps
Package summary
Share
44
issues
3
critical severity
vulnerability
1
license
2
29
high severity
vulnerability
12
license
3
meta
14
9
moderate severity
vulnerability
9
3
low severity
vulnerability
1
license
2
11
licenses
193
MIT
39
ISC
9
BSD-3-Clause
18
other licenses
Apache-2.0
7
BSD-2-Clause
3
N/A
2
Unlicense
2
+ 4 more
Package created
24 Oct 2013
Version published
7 Aug 2017
Maintainers
3
Total deps
259
Direct deps
32
License
MIT

Issues

44

3 critical severity issues

critical
Recommendation: Upgrade to version 4.17.12 or later
via: nash@2.0.4
Recommendation: Check the package code and files for license information
via: shrink-ray@0.1.3
Recommendation: Check the package code and files for license information
via: join-path@1.1.1
Collapse
Expand

29 high severity issues

high
Recommendation: Upgrade to version 5.0.2 or later
via: superstatic@4.2.1
Recommendation: Upgrade to version 5.0.2 or later
via: superstatic@4.2.1
Recommendation: Upgrade to version 3.2.2 or later
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 4.2.1 or later
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 2.6.9 or later
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 4.17.11 or later
via: nash@2.0.4
Recommendation: Upgrade to version 4.2.1 or later
via: update-notifier@1.0.3
Recommendation: Upgrade to version 9.0.1 or later
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 4.4.18 or later
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 4.17.19 or later
via: nash@2.0.4
Recommendation: None
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 4.17.21 or later
via: nash@2.0.4
Recommendation: Validate that the package complies with your license policy
via: shrink-ray@0.1.3
Recommendation: Validate that the license expression complies with your license policy
via: update-notifier@1.0.3 & others
Recommendation: Validate that the package complies with your license policy
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: iltorb@1.3.4 & others
via: iltorb@1.3.4 & others
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: shrink-ray@0.1.3
via: update-notifier@1.0.3
via: shrink-ray@0.1.3
Collapse
Expand

9 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: nash@2.0.4
Recommendation: Upgrade to version 11.8.5 or later
via: update-notifier@1.0.3
Recommendation: Upgrade to version 6.12.3 or later
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 2.0.0 or later
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 4.17.21 or later
via: nash@2.0.4
Recommendation: Upgrade to version 4.1.3 or later
via: shrink-ray@0.1.3
Recommendation: None
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 6.2.1 or later
via: shrink-ray@0.1.3
Recommendation: Upgrade to version 4.17.5 or later
via: nash@2.0.4
Collapse
Expand

3 low severity issues

low
Recommendation: Upgrade to version 2.6.9 or later
via: shrink-ray@0.1.3
Recommendation: Read and validate the license terms
via: shrink-ray@0.1.3
Recommendation: Read and validate the license terms
via: shrink-ray@0.1.3
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
193 Packages, Including:
@types/keyv@3.1.4
@types/node@20.12.8
@types/responselike@1.0.3
accepts@1.3.8
ajv@4.11.8
ansi-regex@2.1.1
ansi-styles@2.2.1
array-flatten@1.1.1
array-flatten@3.0.0
as-array@1.0.0
as-array@2.0.0
asn1@0.2.6
assert-plus@0.2.0
assert-plus@1.0.0
async@1.5.2
asynckit@0.4.0
aws4@1.12.0
balanced-match@1.0.2
basic-auth-connect@1.0.0
basic-auth@2.0.1
bluebird@2.11.0
boxen@0.6.0
brace-expansion@1.1.11
bytes@2.2.0
bytes@3.0.0
call-bind@1.0.7
camelcase@2.1.1
capture-stack-trace@1.0.2
chalk@1.1.3
cli-boxes@1.0.0
clone@1.0.4
co@4.6.0
code-point-at@1.1.0
combined-stream@1.0.8
commander@2.20.3
compare-semver@1.1.0
compressible@2.0.18
compression@1.7.4
concat-map@0.0.1
connect-query@1.0.0
connect@3.7.0
core-util-is@1.0.2
core-util-is@1.0.3
create-error-class@3.0.2
dashdash@1.14.1
debug@2.2.0
debug@2.6.9
deep-extend@0.6.0
defaults@1.0.4
define-data-property@1.1.4

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
39 Packages, Including:
abbrev@1.1.1
ansi-align@1.1.0
aproba@1.2.0
are-we-there-yet@1.1.7
block-stream@0.0.9
char-spinner@1.0.1
console-control-strings@1.1.0
fs.realpath@1.0.0
fstream-ignore@1.0.5
fstream@1.0.12
gauge@2.7.4
glob@7.2.3
graceful-fs@4.2.11
har-schema@1.0.5
har-validator@4.2.1
has-unicode@2.0.1
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
json-stringify-safe@5.0.1
lru-cache@4.1.5
minimatch@3.1.2
nopt@4.0.3
npmlog@4.1.2
once@1.4.0
osenv@0.1.5
pseudomap@1.0.2
rimraf@2.7.1
semver@5.7.2
set-blocking@2.0.0
setprototypeof@1.2.0
signal-exit@3.0.7
slide@1.1.6
tar@2.2.2
uid-number@0.0.6
wide-align@1.1.5
wrappy@1.0.2
write-file-atomic@1.3.4
yallist@2.1.2

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
bcrypt-pbkdf@1.0.2
boom@2.10.1
cryptiles@2.0.5
duplexer2@0.1.4
hawk@3.1.3
hoek@2.16.3
node-pre-gyp@0.6.39
qs@6.4.1
tough-cookie@2.3.4

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
7 Packages, Including:
aws-sign2@0.6.0
caseless@0.12.0
detect-libc@1.0.3
forever-agent@0.6.1
oauth-sign@0.8.2
request@2.81.0
tunnel-agent@0.6.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
configstore@2.1.0
tar-pack@3.4.1
update-notifier@1.0.3

N/A

N/A
2 Packages, Including:
ms@0.7.1
valid-url@1.0.9

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
2 Packages, Including:
stream-buffers@3.0.2
tweetnacl@0.14.5

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

Public Domain

Invalid
Not OSI Approved
1 Packages, Including:
jsonify@0.0.1

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

BSD

Invalid
Not OSI Approved
1 Packages, Including:
sntp@1.0.9
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

32
All Dependencies CSV
β“˜ This is a list of superstatic 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
as-array2.0.01.33 kBMIT
prod
async1.5.238.01 kBMIT
prod
basic-auth-connect1.0.02.77 kBMIT
prod
chalk1.1.35.11 kBMIT
prod
char-spinner1.0.12.21 kBISC
prod
compare-semver1.1.01.45 kBMIT
prod
compression1.7.47.64 kBMIT
prod
connect-query1.0.01.34 kBMIT
prod
connect3.7.026.84 kBMIT
prod
destroy1.2.03.3 kBMIT
prod
fast-url-parser1.1.39.67 kBMIT
prod
fs-extra0.30.024.22 kBMIT
prod
glob-slasher1.0.12.59 kBMIT
prod
glob7.2.315.08 kBISC
prod
home-dir1.0.01.4 kBMIT
prod
iltorb1.3.41.96 MBMIT
prod optional
2
is-url1.2.42.41 kBMIT
prod
join-path1.1.12.16 kBMIT
prod
1
lodash4.17.21311.49 kBMIT
prod
mime-types2.1.355.46 kBMIT
prod optional
minimatch3.1.211.66 kBISC
prod optional
morgan1.10.09.37 kBMIT
prod
nash2.0.415.76 kBMIT
prod
1
3
3
on-finished2.4.14.93 kBMIT
prod
on-headers1.0.23.15 kBMIT
prod optional
path-to-regexp1.8.08.52 kBMIT
prod
router1.3.812.9 kBMIT
prod
rsvp3.6.2166.55 kBMIT
prod
shrink-ray0.1.310.26 kBMIT
prod optional
1
22
5
3
string-length1.0.11.57 kBMIT
prod
try-require1.2.12.07 kBMIT
prod
update-notifier1.0.34.3 kBBSD-2-Clause
prod
3
1

Visualizations