Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 9, 2024 via pnpm

tsup 6.7.0

Bundle your TypeScript library with no config, powered by esbuild
Package summary
Share
7
issues
3
high severity
license
2
meta
1
2
moderate severity
meta
2
2
low severity
license
2
6
licenses
103
MIT
14
ISC
2
Apache-2.0
4
other licenses
BlueOak-1.0.0
2
BSD-3-Clause
1
BSD-2-Clause
1
Package created
10 May 2020
Version published
19 Mar 2023
Maintainers
2
Total deps
123
Direct deps
14
License
MIT

Issues

7

3 high severity issues

high
Recommendation: Read and validate the license terms
via: sucrase@3.35.0
Recommendation: Read and validate the license terms
via: sucrase@3.35.0
via: bundle-require@4.1.0 & others
Collapse
Expand

2 moderate severity issues

moderate
via: bundle-require@4.1.0
via: bundle-require@4.1.0
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: sucrase@3.35.0
Recommendation: Read and validate the license terms
via: sucrase@3.35.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
103 Packages, Including:
@esbuild/android-arm64@0.17.19
@esbuild/android-arm@0.17.19
@esbuild/android-x64@0.17.19
@esbuild/darwin-arm64@0.17.19
@esbuild/darwin-x64@0.17.19
@esbuild/freebsd-arm64@0.17.19
@esbuild/freebsd-x64@0.17.19
@esbuild/linux-arm64@0.17.19
@esbuild/linux-arm@0.17.19
@esbuild/linux-ia32@0.17.19
@esbuild/linux-loong64@0.17.19
@esbuild/linux-mips64el@0.17.19
@esbuild/linux-ppc64@0.17.19
@esbuild/linux-riscv64@0.17.19
@esbuild/linux-s390x@0.17.19
@esbuild/linux-x64@0.17.19
@esbuild/netbsd-x64@0.17.19
@esbuild/openbsd-x64@0.17.19
@esbuild/sunos-x64@0.17.19
@esbuild/win32-arm64@0.17.19
@esbuild/win32-ia32@0.17.19
@esbuild/win32-x64@0.17.19
@jridgewell/gen-mapping@0.3.5
@jridgewell/resolve-uri@3.1.2
@jridgewell/set-array@1.2.1
@jridgewell/sourcemap-codec@1.4.15
@jridgewell/trace-mapping@0.3.25
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.walk@1.2.8
@pkgjs/parseargs@0.11.0
ansi-regex@6.0.1
ansi-styles@6.2.1
any-promise@1.3.0
array-union@2.1.0
balanced-match@1.0.2
binary-extensions@2.3.0
brace-expansion@2.0.1
braces@3.0.2
bundle-require@4.1.0
cac@6.7.14
chokidar@3.6.0
commander@4.1.1
cross-spawn@7.0.3
debug@4.3.4
dir-glob@3.0.1
eastasianwidth@0.2.0
emoji-regex@9.2.2
esbuild@0.17.19
execa@5.1.1

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
14 Packages, Including:
@isaacs/cliui@8.0.2
anymatch@3.1.3
fastq@1.17.1
foreground-child@3.1.1
glob-parent@5.1.2
glob@10.3.12
isexe@2.0.0
lru-cache@10.2.2
minimatch@9.0.4
minipass@7.1.0
signal-exit@3.0.7
signal-exit@4.1.0
which@2.0.2
yaml@1.10.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
human-signals@2.1.0
ts-interface-checker@0.1.13

Blue Oak Model License 1.0.0

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
2 Packages, Including:
jackspeak@2.3.6
path-scurry@1.10.2

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
source-map@0.8.0-beta.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
webidl-conversions@4.0.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

14
All Dependencies CSV
β“˜ This is a list of tsup 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
bundle-require4.1.024.72 kBMIT
prod
1
2
cac6.7.1421.41 kBMIT
prod
chokidar3.6.025.83 kBMIT
prod
debug4.3.412.94 kBMIT
prod
esbuild0.17.1928.36 kBMIT
prod peer
1
execa5.1.114.15 kBMIT
prod
globby11.1.06.23 kBMIT
prod
joycon3.1.14.33 kBMIT
prod
postcss-load-config3.1.46.89 kBMIT
prod
resolve-from5.0.02.28 kBMIT
prod
rollup3.29.4528.36 kBMIT
prod
source-map0.8.0-beta.058.64 kBBSD-3-Clause
prod
sucrase3.35.0189.24 kBMIT
prod
2
2
tree-kill1.2.23.17 kBMIT
prod

Visualizations