Skip to content

Instantly share code, notes, and snippets.

@luebken
Created September 6, 2017 08:10
Show Gist options
  • Save luebken/7e547a855a9f36a9eb0e09e6649a3cc1 to your computer and use it in GitHub Desktop.
Save luebken/7e547a855a9f36a9eb0e09e6649a3cc1 to your computer and use it in GitHub Desktop.
example
{
"main": {
"name": "express",
"ecosystem": "npm",
"repository": "https://github.com/expressjs/express"
},
"librariesio": {
"name": "express",
"platform": "NPM",
"description": "Fast, unopinionated, minimalist web framework",
"homepage": "http://expressjs.com/",
"normalized_licenses": [
"MIT"
],
"rank": "28",
"latest_release_published_at": "2017-03-06T13:51:05.877Z",
"latest_release_number": "5.0.0-alpha.5",
"keywords": [
"express",
"framework",
"sinatra",
"web",
"rest",
"restful",
"router",
"app",
"api"
]
},
"versioneye": {
"name": "express",
"language": "nodejs",
"description": "Fast, unopinionated, minimalist web framework",
"version": "4.15.4"
},
"npms": {
"collected": {
"metadata": {
"name": "express",
"description": "Fast, unopinionated, minimalist web framework",
"version": "4.15.4",
"keywords": [
"express",
"framework",
"sinatra",
"web",
"rest",
"restful",
"router",
"app",
"api"
],
"links": {
"homepage": "http://expressjs.com/",
"repository": "https://github.com/expressjs/express"
},
"license": "MIT",
"dependencies": [
{
"name": "accepts",
"version": "~1.3.3"
},
{
"name": "array-flatten",
"version": "1.1.1"
},
{
"name": "content-disposition",
"version": "0.5.2"
},
{
"name": "content-type",
"version": "~1.0.2"
},
{
"name": "cookie",
"version": "0.3.1"
},
{
"name": "cookie-signature",
"version": "1.0.6"
},
{
"name": "debug",
"version": "2.6.8"
},
{
"name": "depd",
"version": "~1.1.1"
},
{
"name": "encodeurl",
"version": "~1.0.1"
},
{
"name": "escape-html",
"version": "~1.0.3"
},
{
"name": "etag",
"version": "~1.8.0"
},
{
"name": "finalhandler",
"version": "~1.0.4"
},
{
"name": "fresh",
"version": "0.5.0"
},
{
"name": "merge-descriptors",
"version": "1.0.1"
},
{
"name": "methods",
"version": "~1.1.2"
},
{
"name": "on-finished",
"version": "~2.3.0"
},
{
"name": "parseurl",
"version": "~1.3.1"
},
{
"name": "path-to-regexp",
"version": "0.1.7"
},
{
"name": "proxy-addr",
"version": "~1.1.5"
},
{
"name": "qs",
"version": "6.5.0"
},
{
"name": "range-parser",
"version": "~1.2.0"
},
{
"name": "send",
"version": "0.15.4"
},
{
"name": "serve-static",
"version": "1.12.4"
},
{
"name": "setprototypeof",
"version": "1.0.3"
},
{
"name": "statuses",
"version": "~1.3.1"
},
{
"name": "type-is",
"version": "~1.6.15"
},
{
"name": "utils-merge",
"version": "1.0.0"
},
{
"name": "vary",
"version": "~1.1.1"
}
]
}
},
"evaluation": {
"quality": {
"carefulness": 0.9999999999999999,
"tests": 1,
"health": 0.7142857142857143,
"branding": 1
}
}
},
"snyk": {
"readme": "## Overview\n[`express`](https://www.npmjs.com/package/express) is a minimalist web framework.\n\nVulnerable versions of this package do not enforce the user's browser to set a specific charset in the content-type header while displaying 400 level response messages. This could be used by remote attackers to perform a cross-site scripting attack, by using non-standard encodings like UTF-7.\n\n## Recommendations\nUpdate express to `3.11.0` or higher for the 3.x versions or `4.5.0` or higher for the 4.x versions.\n\n## References\n- [GitHub release 3.11.0](https://github.com/expressjs/express/releases/tag/3.11.0)\n- [GitHub release 4.5.0](https://github.com/expressjs/express/releases/tag/4.5.0)\n"
},
"daviddm": {
"status": "notsouptodate",
"deps": [
{
"name": "accepts",
"required": "~1.3.3",
"stable": "1.3.4",
"latest": "1.3.4",
"status": "uptodate"
},
{
"name": "array-flatten",
"required": "1.1.1",
"stable": "2.1.1",
"latest": "2.1.1",
"status": "outofdate"
},
{
"name": "content-disposition",
"required": "0.5.2",
"stable": "0.5.2",
"latest": "0.5.2",
"status": "uptodate"
},
{
"name": "content-type",
"required": "~1.0.2",
"stable": "1.0.2",
"latest": "1.0.2",
"status": "uptodate"
},
{
"name": "cookie",
"required": "0.3.1",
"stable": "0.3.1",
"latest": "0.3.1",
"status": "uptodate"
},
{
"name": "cookie-signature",
"required": "1.0.6",
"stable": "1.0.6",
"latest": "1.0.6",
"status": "uptodate"
},
{
"name": "debug",
"required": "2.6.8",
"stable": "3.0.1",
"latest": "3.0.1",
"status": "outofdate"
},
{
"name": "depd",
"required": "~1.1.1",
"stable": "1.1.1",
"latest": "1.1.1",
"status": "uptodate"
},
{
"name": "encodeurl",
"required": "~1.0.1",
"stable": "1.0.1",
"latest": "1.0.1",
"status": "uptodate"
},
{
"name": "escape-html",
"required": "~1.0.3",
"stable": "1.0.3",
"latest": "1.0.3",
"status": "uptodate"
},
{
"name": "etag",
"required": "~1.8.0",
"stable": "1.8.0",
"latest": "1.8.0",
"status": "uptodate"
},
{
"name": "finalhandler",
"required": "~1.0.4",
"stable": "1.0.4",
"latest": "1.0.4",
"status": "uptodate"
},
{
"name": "fresh",
"required": "0.5.0",
"stable": "0.5.0",
"latest": "0.5.0",
"status": "uptodate"
},
{
"name": "merge-descriptors",
"required": "1.0.1",
"stable": "1.0.1",
"latest": "1.0.1",
"status": "uptodate"
},
{
"name": "methods",
"required": "~1.1.2",
"stable": "1.1.2",
"latest": "1.1.2",
"status": "uptodate"
},
{
"name": "on-finished",
"required": "~2.3.0",
"stable": "2.3.0",
"latest": "2.3.0",
"status": "uptodate"
},
{
"name": "parseurl",
"required": "~1.3.1",
"stable": "1.3.1",
"latest": "1.3.1",
"status": "uptodate"
},
{
"name": "path-to-regexp",
"required": "0.1.7",
"stable": "2.0.0",
"latest": "2.0.0",
"status": "outofdate"
},
{
"name": "proxy-addr",
"required": "~1.1.5",
"stable": "2.0.0",
"latest": "2.0.0",
"status": "outofdate"
},
{
"name": "qs",
"required": "6.5.0",
"stable": "6.5.0",
"latest": "6.5.0",
"status": "uptodate"
},
{
"name": "range-parser",
"required": "~1.2.0",
"stable": "1.2.0",
"latest": "1.2.0",
"status": "uptodate"
},
{
"name": "send",
"required": "0.15.4",
"stable": "0.15.4",
"latest": "0.15.4",
"status": "uptodate"
},
{
"name": "serve-static",
"required": "1.12.4",
"stable": "1.12.4",
"latest": "1.12.4",
"status": "uptodate"
},
{
"name": "setprototypeof",
"required": "1.0.3",
"stable": "1.0.3",
"latest": "1.0.3",
"status": "uptodate"
},
{
"name": "statuses",
"required": "~1.3.1",
"stable": "1.3.1",
"latest": "1.3.1",
"status": "uptodate"
},
{
"name": "type-is",
"required": "~1.6.15",
"stable": "1.6.15",
"latest": "1.6.15",
"status": "uptodate"
},
{
"name": "utils-merge",
"required": "1.0.0",
"stable": "1.0.0",
"latest": "1.0.0",
"status": "uptodate"
},
{
"name": "vary",
"required": "~1.1.1",
"stable": "1.1.1",
"latest": "1.1.1",
"status": "uptodate"
}
]
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment