Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 29, 2024 via npm
Package summary
Share
84
issues
7
critical severity
vulnerability
2
license
5
50
high severity
vulnerability
11
license
5
meta
34
23
moderate severity
vulnerability
18
meta
5
4
low severity
license
4
17
licenses
762
MIT
45
ISC
25
BSD-3-Clause
41
other licenses
BSD-2-Clause
10
Apache-2.0
10
N/A
5
0BSD
3
+ 10 more
Package created
22 Mar 2015
Version published
20 Oct 2021
Maintainers
99
Total deps
873
Direct deps
76
License
MIT

Issues

84

7 critical severity issues

critical
Recommendation: Update vtex to 2.84.1
via: eventsource@1.0.7
Recommendation: Update vtex to 2.84.1
via: cli-table2@0.2.0
Recommendation: Check the package code and files for license information
via: @vtex/node-error-report@0.0.2
Recommendation: Check the package code and files for license information
via: @vtex/toolbelt-message-renderer@0.0.1
Recommendation: Check the package code and files for license information
via: unzip-stream@0.3.4
Recommendation: Check the package code and files for license information
via: cli-table@0.3.11
Recommendation: Check the package code and files for license information
via: koa@2.15.3
Collapse
Expand

50 high severity issues

high
Recommendation: Update vtex to 2.84.1
via: @vtex/api@3.77.0
Recommendation: Update vtex to 2.84.1
via: @vtex/api@3.77.0
Recommendation: Update vtex to 2.84.1
via: @vtex/api@3.77.0
Recommendation: Update vtex to 2.84.1
via: globby@8.0.2
Recommendation: Update vtex to 2.84.1
via: latest-version@4.0.0
Recommendation: Update vtex to 2.84.1
via: cli-table2@0.2.0
Recommendation: Update vtex to 2.84.1
via: cli-table2@0.2.0
Recommendation: Update vtex to 2.84.1
via: cli-table2@0.2.0
Recommendation: Update vtex to 2.84.1
via: @oclif/plugin-help@2.2.3
Recommendation: Validate that the package complies with your license policy
via: unzip-stream@0.3.4
Recommendation: Validate that the package complies with your license policy
via: unzip-stream@0.3.4
Recommendation: Validate that the package complies with your license policy
via: globby@8.0.2
Recommendation: Validate that the package complies with your license policy
via: qrcode-terminal@0.12.0
Recommendation: Validate that the license expression complies with your license policy
via: latest-version@4.0.0 & others
via: @vtex/api@3.77.0
via: @vtex/cli-plugin-autoupdate@0.0.2 & others
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0 & others
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/cli-plugin-autoupdate@0.0.2 & others
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: chokidar@3.3.1
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: request@2.88.2
via: @vtex/api@3.77.0
via: request@2.88.2
via: globby@8.0.2
via: globby@8.0.2
via: globby@8.0.2
via: @vtex/api@3.77.0
via: globby@8.0.2
via: @vtex/cli-plugin-plugins@1.13.2 & others
Collapse
Expand

23 moderate severity issues

moderate
Recommendation: Update vtex to 2.84.1
via: ajv@6.10.2
Recommendation: Update vtex to 2.84.1
via: @vtex/api@3.77.0
Recommendation: Update vtex to 2.84.1
via: @vtex/api@3.77.0
Recommendation: Update vtex to 2.84.1
via: @vtex/api@3.77.0
Recommendation: Update vtex to 2.84.1
via: @vtex/api@3.77.0
Recommendation: Update vtex to 2.84.1
via: @vtex/api@3.77.0
Recommendation: Update vtex to 2.84.1
via: latest-version@4.0.0 & others
Recommendation: Update vtex to 2.84.1
via: jsonwebtoken@8.5.1
Recommendation: Update vtex to 2.84.1
via: jsonwebtoken@8.5.1
Recommendation: Update vtex to 2.84.1
via: cli-table2@0.2.0
Recommendation: Update vtex to 2.84.1
via: cli-table2@0.2.0
Recommendation: Update vtex to 2.84.1
via: cli-table2@0.2.0
Recommendation: Update vtex to 2.84.1
via: node-notifier@6.0.0
Recommendation: Update vtex to 2.84.1
via: request@2.88.2
Recommendation: Update vtex to 2.84.1
via: semver@7.1.3
Recommendation: Update vtex to 2.84.1
via: tar@4.4.19
Recommendation: Update vtex to 2.84.1
via: request@2.88.2
via: @vtex/node-error-report@0.0.2
via: @vtex/toolbelt-message-renderer@0.0.1
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
via: @vtex/api@3.77.0
Collapse
Expand

4 low severity issues

low
Recommendation: Read and validate the license terms
via: unzip-stream@0.3.4
Recommendation: Read and validate the license terms
via: unzip-stream@0.3.4
Recommendation: Read and validate the license terms
via: globby@8.0.2
Recommendation: Read and validate the license terms
via: qrcode-terminal@0.12.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
762 Packages, Including:
@types/node@10.17.60
@apollographql/apollo-tools@0.5.4
@apollographql/graphql-playground-html@1.6.27
@apollographql/graphql-upload-8-fork@8.1.4
@babel/runtime@7.24.4
@colors/colors@1.6.0
@mrmlnc/readdir-enhanced@2.2.1
@nodelib/fs.scandir@2.1.5
@nodelib/fs.stat@2.0.5
@nodelib/fs.stat@1.1.3
@nodelib/fs.walk@1.2.8
@oclif/color@0.1.2
ansi-regex@4.1.1
chalk@3.0.0
ansi-styles@4.3.0
supports-color@7.2.0
color-convert@2.0.1
color-name@1.1.4
has-flag@4.0.0
strip-ansi@5.2.0
@oclif/command@1.8.36
@oclif/config@1.18.17
array-union@2.1.0
dir-glob@3.0.1
fast-glob@3.3.2
globby@11.1.0
ignore@5.3.1
micromatch@4.0.5
path-type@4.0.0
slash@3.0.0
@oclif/errors@1.3.6
fs-extra@8.1.0
@oclif/help@1.0.15
@oclif/config@1.18.16
chalk@4.1.2
wrap-ansi@6.2.0
@oclif/parser@3.8.17
@oclif/plugin-help@2.2.3
chalk@2.4.2
emoji-regex@7.0.3
is-fullwidth-code-point@2.0.0
string-width@3.1.0
widest-line@2.0.1
ansi-regex@3.0.1
string-width@2.1.1
strip-ansi@4.0.0
wrap-ansi@4.0.0
@oclif/screen@1.0.4
@sindresorhus/is@0.7.0
@szmarczak/http-timer@1.1.2

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
45 Packages, Including:
@josephg/resolvable@1.0.1
lru-cache@6.0.0
semver@7.6.0
yallist@4.0.0
@oclif/linewrap@1.0.0
semver@5.7.2
ansi-align@3.0.1
anymatch@3.1.3
at-least-node@1.0.0
chownr@1.1.4
which@1.3.1
glob-parent@3.1.0
fastq@1.17.1
fs-minipass@1.2.7
fs.realpath@1.0.0
glob@7.2.3
glob-parent@5.1.2
graceful-fs@4.2.11
har-schema@2.0.0
http-call@5.3.0
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
isexe@2.0.0
json-stringify-safe@5.0.1
log-chopper@1.0.2
lru-cache@5.1.1
semver@6.3.1
minimatch@3.1.2
minipass@2.9.0
mute-stream@0.0.8
once@1.4.0
pseudomap@1.0.2
mute-stream@0.0.7
semver@7.1.3
setprototypeof@1.2.0
signal-exit@3.0.7
tar@4.4.19
lru-cache@4.1.5
write-file-atomic@2.4.3
yallist@2.1.2
which@2.0.2
wrappy@1.0.2
write-file-atomic@3.0.3
yallist@3.1.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
25 Packages, Including:
@apollo/protobufjs@1.2.2
@protobufjs/aspromise@1.1.2
@protobufjs/base64@1.1.2
@protobufjs/codegen@2.0.4
@protobufjs/eventemitter@1.1.0
@protobufjs/fetch@1.1.0
@protobufjs/float@1.0.2
@protobufjs/inquire@1.1.0
@protobufjs/path@1.1.2
@protobufjs/pool@1.1.0
@protobufjs/utf8@1.1.0
bcrypt-pbkdf@1.0.2
buffer-equal-constant-time@1.0.1
dataloader@1.4.0
diff@3.5.0
duplexer3@0.1.5
filesize@6.4.0
ieee754@1.2.1
js-base64@2.6.4
qs@6.12.1
ramda-adjunct@2.23.0
qs@6.5.3
source-map@0.5.7
sprintf-js@1.0.3
tough-cookie@2.5.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
10 Packages, Including:
@yarnpkg/lockfile@1.1.0
configstore@5.0.1
esprima@4.0.1
http-cache-semantics@3.8.1
update-notifier@3.0.1
configstore@4.0.0
http-cache-semantics@4.1.1
uri-js@4.4.1
webidl-conversions@3.0.1
yarn@1.22.22

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
10 Packages, Including:
aws-sign2@0.7.0
axios-retry@3.9.1
caseless@0.12.0
ecdsa-sig-formatter@1.0.11
forever-agent@0.6.1
long@4.0.0
oauth-sign@0.9.0
request@2.88.2
ts-toolbelt@6.15.5
tunnel-agent@0.6.0

N/A

N/A
5 Packages, Including:
@vtex/node-error-report@0.0.2
@vtex/toolbelt-message-renderer@0.0.1
buffers@0.1.1
cli-table@0.3.11
only@0.0.2

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
3 Packages, Including:
tslib@2.6.2
password-prompt@1.1.3
tslib@1.14.1

(MIT OR CC0-1.0)

Public Domain
3 Packages, Including:
type-fest@0.8.1
type-fest@0.3.1
type-fest@0.21.3

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
chainsaw@0.1.0
traverse@0.3.9

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

BSD

Invalid
Not OSI Approved
1 Packages, Including:
glob-to-regexp@0.3.0

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

(WTFPL OR MIT)

Permissive
1 Packages, Including:
path-is-inside@1.0.2

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
qrcode-terminal@0.12.0

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

(MIT AND BSD-3-Clause)

Permissive
1 Packages, Including:
sha.js@2.4.11

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

76
All Dependencies CSV
β“˜ This is a list of vtex 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@oclif/command1.8.367.1 kBMIT
prod
@oclif/config1.18.1714.26 kBMIT
prod peer
@oclif/plugin-help2.2.310.81 kBMIT
prod
1
@tiagonapoli/oclif-plugin-spaced-commands0.0.63.78 kBMIT
prod
@vtex/api3.77.082.41 kBMIT
prod
27
8
@vtex/cli-plugin-abtest0.1.1157.76 kBMIT
prod
@vtex/cli-plugin-autoupdate0.0.27.71 kBMIT
prod
2
@vtex/cli-plugin-deploy0.3.1162.94 kBMIT
prod
@vtex/cli-plugin-deps0.1.1157.23 kBMIT
prod
@vtex/cli-plugin-edition0.1.1156.23 kBMIT
prod
@vtex/cli-plugin-plugins1.13.216.95 kBMIT
prod
3
@vtex/cli-plugin-whoami0.2.2155.94 kBMIT
prod
@vtex/cli-plugin-workspace1.0.1160.08 kBMIT
prod
@vtex/node-error-report0.0.26.43 kBUNKNOWN
prod
1
1
@vtex/toolbelt-message-renderer0.0.12.71 kBUNKNOWN
prod
1
1
@yarnpkg/lockfile1.1.073.35 kBBSD-2-Clause
prod
ajv6.10.2194.35 kBMIT
prod
1
ansi-escapes4.3.25.13 kBMIT
prod
any-promise1.3.07.43 kBMIT
prod
archiver3.1.111.66 kBMIT
prod
async-retry1.2.32.57 kBMIT
prod
bluebird3.7.2136.03 kBMIT
prod
boxen4.2.04.44 kBMIT
prod
chalk2.3.29.13 kBMIT
prod
child-process-es6-promise1.2.13.98 kBMIT
prod
chokidar3.3.125.01 kBMIT
prod
1
cli-table0.3.115.94 kBUNKNOWN
prod
1
cli-table20.2.048.26 kBMIT
prod
1
3
3
clipboardy2.1.0364.93 kBMIT
prod
co-body6.1.03.85 kBMIT
prod
configstore5.0.13.32 kBBSD-2-Clause
prod
csvtojson2.0.101.09 MBMIT
prod
debounce1.2.14.11 kBMIT
prod
detect-port1.5.14.23 kBMIT
prod
diff3.5.0185.16 kBBSD-3-Clause
prod
enquirer2.3.646.72 kBMIT
prod
eventsource1.0.7118.3 kBMIT
prod
1
extendable-error0.1.72.4 kBMIT
prod
fs-extra7.0.131.33 kBMIT
prod
get-stream4.0.03.29 kBMIT
prod
globby8.0.24.65 kBMIT
prod
6
1
graphql14.7.0379.32 kBMIT
prod peer
indent-string4.0.02.02 kBMIT
prod
is-docker2.2.11.65 kBMIT
prod
is-wsl2.2.01.96 kBMIT
prod
js-yaml3.13.172.31 kBMIT
prod
jsonwebtoken8.5.121.01 kBMIT
prod
3
koa2.15.394.29 kBMIT
prod
1
latest-version4.0.01.68 kBMIT
prod
2
1
moment2.24.0517.34 kBMIT
prod
2
node-notifier6.0.01.88 MBMIT
prod
1
numbro2.1.0223.12 kBMIT
prod
open7.4.212.37 kBMIT
prod
opn5.2.09.04 kBMIT
prod
ora4.1.16.51 kBMIT
prod
pipe-streams-to-promise0.2.03.14 kBMIT
prod
prompt-confirm2.0.43.57 kBMIT
prod
prompts2.3.230.3 kBMIT
prod
proper-lockfile4.1.28.52 kBMIT
prod
qrcode-terminal0.12.051.46 kBApache 2.0
prod
1
1
ramda0.25.0237.82 kBMIT
prod
ramda-adjunct2.23.0385.8 kBBSD-3-Clause
prod
randomstring1.1.54.27 kBMIT
prod
request2.88.257.83 kBApache-2.0
prod
3
2
semver7.1.321.62 kBISC
prod
1
semver-diff2.1.01.74 kBMIT
prod
supports-hyperlinks2.3.03.01 kBMIT
prod
tar4.4.1938.02 kBISC
prod
1
tslib1.14.17.43 kB0BSD
prod
unzip-stream0.3.439.27 kBMIT
prod
1
2
2
update-notifier3.0.15.89 kBBSD-2-Clause
prod
1
1
v8-compile-cache2.4.05.11 kBMIT
prod
winston3.2.173.01 kBMIT
prod
winston-transport4.3.030.17 kBMIT
prod
ws7.5.928.37 kBMIT
prod
yarn1.22.225.09 MBBSD-2-Clause
prod
1

Visualizations