kyma-project/kyma 软件分析报告

基础信息

项目名称:kyma-project/kyma

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1719617300462174208/1719617300583809024

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
node-tar 路径遍历漏洞 路径遍历 MPS-2021-11547 CVE-2021-32804 高危
node-tar 路径遍历漏洞 在文件访问前对链接解析不恰当(链接跟随) MPS-2021-11548 CVE-2021-32803 高危
nanoid 不正确的类型转换 MPS-2021-19605 CVE-2021-23566 中危
Npm Node-tar 后置链接漏洞 在文件访问前对链接解析不恰当(链接跟随) MPS-2021-28486 CVE-2021-37701 高危
Npm Node-tar 后置链接漏洞 在文件访问前对链接解析不恰当(链接跟随) MPS-2021-28488 CVE-2021-37712 高危
node-tar 路径遍历漏洞 路径遍历 MPS-2021-28489 CVE-2021-37713 高危
Axios 拒绝服务漏洞 拒绝服务 MPS-2021-30688 CVE-2021-3749 高危
json-schema 安全漏洞 原型污染 MPS-2021-34478 CVE-2021-3918 严重
npm path-parse 安全漏洞 拒绝服务 MPS-2021-6165 CVE-2021-23343 高危
ws 存在拒绝服务漏洞 拒绝服务 MPS-2021-7109 CVE-2021-32640 中危
Digital Bazaar Forge 存在输入验证错误漏洞 跨站重定向 MPS-2022-0421 CVE-2022-0122 中危
follow-redirects 侵犯隐私 MPS-2022-0815 CVE-2022-0155 中危
node-forge 原型污染 MPS-2022-13920 中危
tar 正则表达式拒绝服务漏洞 拒绝服务 MPS-2022-14081 低危
follow-redirects 未授权敏感信息泄露 MPS-2022-3636 CVE-2022-0536 中危
node-forge 密码签名验证不当漏洞 密码学签名的验证不恰当 MPS-2022-3738 CVE-2022-24771 高危
node-forge 密码签名验证不当漏洞 密码学签名的验证不恰当 MPS-2022-3739 CVE-2022-24772 高危
node-forge 密码签名验证不当漏洞 密码学签名的验证不恰当 MPS-2022-3740 CVE-2022-24773 中危
http-cache-semantics 安全漏洞 ReDoS MPS-2022-5164 CVE-2022-25881 高危
mocha ReDoS 漏洞 ReDoS MPS-2022-54598 高危
Google Golang 资源管理错误漏洞 MPS-2022-58307 CVE-2022-41723 高危
minimatch 资源管理错误漏洞 拒绝服务 MPS-2022-59845 CVE-2022-3517 高危
Go-Yaml 安全漏洞 反序列化 MPS-2022-8233 CVE-2022-28948 高危
word-wrap 安全漏洞 ReDoS MPS-2023-5109 CVE-2023-26115 高危
tough-cookie 安全漏洞 原型污染 MPS-2023-5130 CVE-2023-26136 严重
request SSRF防御绕过漏洞 SSRF MPS-2023-7722 CVE-2023-28155 中危
Google Golang 安全漏洞 拒绝服务 MPS-c8am-hbny CVE-2023-39325 高危
NATS Server 安全漏洞 缺少必要的密码学步骤 MPS-cfjx-q6k1 CVE-2023-46129 高危
get-func-name 安全漏洞 ReDoS MPS-cyhe-l36p CVE-2023-43646 高危
tough-cookie 原型污染 MPS-esyq-56vx 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
mocha 8.3.2 直接依赖 建议修复
gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b 3.0.0 间接依赖 建议修复
json-schema 0.2.3 0.4.0 间接依赖 建议修复
word-wrap 1.2.3 1.2.4 间接依赖 建议修复
axios 0.21.1 0.21.3 直接依赖 建议修复
path-parse 1.0.6 1.0.7 间接依赖 建议修复
tar 6.0.5 6.1.9 间接依赖 建议修复
minimatch 3.0.4 3.0.5 间接依赖 建议修复
golang.org/x/net v0.3.1-0.20221206200815-1e63c2f08a10 0.17.0 间接依赖 建议修复
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c 3.0.0 间接依赖 建议修复
tough-cookie 2.5.0 4.1.3 间接依赖 建议修复
golang.org/x/net v0.4.0 0.17.0 间接依赖 建议修复
node-forge 0.10.0 1.3.0 直接依赖 建议修复
nanoid 3.1.20 3.1.31 间接依赖 可选修复
get-func-name 2.0.0 2.0.1 间接依赖 可选修复
request 2.88.2 间接依赖 可选修复
ws 7.4.1 7.4.6 间接依赖 可选修复
follow-redirects 1.13.1 1.14.8 间接依赖 可选修复
golang.org/x/net v0.10.0 0.17.0 间接依赖 可选修复
github.com/nats-io/nats-server/v2 v2.10.3 直接依赖 可选修复
http-cache-semantics 4.1.0 4.1.1 直接依赖 可选修复
github.com/nats-io/nkeys v0.4.5 间接依赖 可选修复
golang.org/x/net v0.8.0 0.17.0 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
Apache-2.0 122
ISC 35
MIT 280
MPL-2.0 2
BSD-3-Clause 66
BSD-2-Clause 8
0BSD 1
Python-2.0 1
Unlicense 2
Apache 2.0 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
k8s.io/gengo v0.0.0-20200114144118-36b2048a9120 间接依赖 go
inherits 2.0.4 间接依赖 npm
globals 13.12.0 间接依赖 npm
github.com/hashicorp/go-multierror v1.1.1 直接依赖 go
browser-stdout 1.3.1 间接依赖 npm
got 11.8.5 间接依赖 npm
google.golang.org/appengine v1.6.8 间接依赖 go
debug 4.2.0 间接依赖 npm
parent-module 1.0.1 间接依赖 npm
golang.org/x/oauth2 v0.0.0-20220223155221-ee480838109b 间接依赖 go
github.com/kyma-project/kyma/components/eventing-controller v0.0.0-20231023131930-0990d091c639 直接依赖 go
end-of-stream 1.4.4 间接依赖 npm
lru-cache 6.0.0 间接依赖 npm
rfc4648 1.4.0 间接依赖 npm
openid-client 4.2.2 间接依赖 npm
esrecurse 4.3.0 间接依赖 npm
is-extglob 2.1.1 间接依赖 npm
golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028 直接依赖 go
uri-js 4.4.0 间接依赖 npm
normalize-path 3.0.0 间接依赖 npm
github.com/imdario/mergo v0.3.12 间接依赖 go
k8s.io/api v0.26.7 直接依赖 go
k8s.io/apimachinery v0.27.4 直接依赖 go
md5 2.3.0 间接依赖 npm
extsprintf 1.3.0 间接依赖 npm
is-fullwidth-code-point 2.0.0 间接依赖 npm
to-regex-range 5.0.1 间接依赖 npm
har-schema 2.0.0 间接依赖 npm
github.com/emicklei/go-restful/v3 v3.11.0 间接依赖 go
is-binary-path 2.1.0 间接依赖 npm
k8s.io/kube-openapi v0.0.0-20200410145947-61e04a5be9a6 间接依赖 go
find-up 5.0.0 间接依赖 npm
clean-stack 2.2.0 间接依赖 npm
mime-db 1.44.0 间接依赖 npm
es5-ext 0.10.53 间接依赖 npm
lodash.merge 4.6.2 间接依赖 npm
github.com/onsi/gomega v1.29.0 直接依赖 go
github.com/kyma-project/kyma/common/logging v0.0.0-20231020092259-d58329d50da1 间接依赖 go
github.com/vrischmann/envconfig v1.3.0 直接依赖 go
k8s.io/utils v0.0.0-20221107191617-1a15be271d1d 间接依赖 go
mimic-fn 2.1.0 间接依赖 npm
wrap-ansi 7.0.0 间接依赖 npm
minizlib 2.1.2 间接依赖 npm
go.uber.org/atomic v1.11.0 直接依赖 go
github.com/go-openapi/swag v0.22.3 间接依赖 go
github.com/google/go-cmp v0.5.9 间接依赖 go
delayed-stream 1.0.0 间接依赖 npm
defer-to-connect 2.0.0 间接依赖 npm
mocha-multi-reporters 1.5.1 直接依赖 npm
github.com/stretchr/objx v0.5.0 间接依赖 go
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd 间接依赖 go
go.uber.org/zap v1.21.0 直接依赖 go
github.com/go-openapi/jsonreference v0.20.1 间接依赖 go
lodash 4.17.21 间接依赖 npm
balanced-match 1.0.0 间接依赖 npm
inflight 1.0.6 间接依赖 npm
ms 2.1.2 间接依赖 npm
github.com/kofalt/go-memoize v0.0.0-20200917044458-9b55a8d73e1c 直接依赖 go
github.com/Masterminds/semver/v3 v3.1.1 间接依赖 go
@kubernetes/client-node 0.15.1 直接依赖 npm
crypt 0.0.2 间接依赖 npm
golang.org/x/net v0.10.0 间接依赖 go
es6-iterator 2.0.3 间接依赖 npm
check-error 1.0.2 间接依赖 npm
gopkg.in/yaml.v3 v3.0.1 间接依赖 go
escalade 3.1.1 间接依赖 npm
github.com/beorn7/perks v1.0.1 间接依赖 go
ansi-colors 4.1.1 间接依赖 npm
k8s.io/utils v0.0.0-20230209194617-a36077c30491 直接依赖 go
@types/keyv 3.1.1 间接依赖 npm
github.com/onrik/logrus v0.9.0 间接依赖 go
tough-cookie 2.5.0 间接依赖 npm
imurmurhash 0.1.4 间接依赖 npm
golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd 间接依赖 go
k8s.io/apimachinery v0.26.0 直接依赖 go
websocket 1.0.34 间接依赖 npm
sigs.k8s.io/yaml v1.3.0 直接依赖 go
make-error 1.3.6 间接依赖 npm
path-is-absolute 1.0.1 间接依赖 npm
github.com/prometheus/common v0.37.0 间接依赖 go
qs 6.5.3 间接依赖 npm
caseless 0.12.0 间接依赖 npm
@panva/asn1.js 1.0.0 间接依赖 npm
golang.org/x/crypto v0.14.0 间接依赖 go
flat 5.0.2 间接依赖 npm
mockserver-client 5.15.0 直接依赖 npm
github.com/spf13/cast v1.4.1 间接依赖 go
golang.org/x/sys v0.4.0 间接依赖 go
get-stream 6.0.0 间接依赖 npm
github.com/google/uuid v1.3.1 直接依赖 go
p-any 3.0.0 间接依赖 npm
github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 间接依赖 go
tunnel-agent 0.6.0 间接依赖 npm
interpret 1.4.0 间接依赖 npm
github.com/mitchellh/reflectwalk v1.0.1 间接依赖 go
jsonpath-plus 0.19.0 间接依赖 npm
clone-response 1.0.2 直接依赖 npm
github.com/rogpeppe/go-internal v1.10.0 间接依赖 go
k8s.io/kube-openapi v0.0.0-20230717233707-2695361300d9 间接依赖 go
golang.org/x/time v0.0.0-20220210224613-90d013bbcef8 间接依赖 go
github.com/prometheus/client_model v0.4.1-0.20230718164431-9a2bf3000d16 间接依赖 go
github.com/klauspost/compress v1.17.0 间接依赖 go
fill-range 7.0.1 间接依赖 npm
golang.org/x/net v0.4.0 间接依赖 go
type-fest 0.20.2 间接依赖 npm
ws 7.4.1 间接依赖 npm
is-plain-obj 2.1.0 间接依赖 npm
require-directory 2.1.1 间接依赖 npm
github.com/go-ozzo/ozzo-validation/v4 v4.3.0 间接依赖 go
growl 1.10.5 间接依赖 npm
github.com/prometheus/client_golang v1.14.0 间接依赖 go
pathval 1.1.1 间接依赖 npm
github.com/go-openapi/jsonreference v0.19.3 间接依赖 go
sigs.k8s.io/controller-runtime v0.14.6 直接依赖 go
github.com/kyma-project/kyma/components/central-application-gateway v0.0.0-20230130154909-4c81ab2cee61 直接依赖 go
type-check 0.4.0 间接依赖 npm
natural-compare 1.4.0 间接依赖 npm
bcrypt-pbkdf 1.0.2 间接依赖 npm
go.uber.org/multierr v1.11.0 间接依赖 go
isstream 0.1.2 间接依赖 npm
callsites 3.1.0 间接依赖 npm
punycode 2.1.1 间接依赖 npm
golang.org/x/tools v0.4.0 直接依赖 go
enquirer 2.3.6 间接依赖 npm
levn 0.4.1 间接依赖 npm
http-signature 1.2.0 间接依赖 npm
github.com/davecgh/go-spew v1.1.1 间接依赖 go
type-detect 4.0.8 间接依赖 npm
github.com/go-logr/zapr v1.2.3 间接依赖 go
github.com/go-logr/logr v0.4.0 间接依赖 go
ajv 6.12.6 间接依赖 npm
go.uber.org/zap v1.26.0 直接依赖 go
github.com/go-logr/zapr v0.4.0 直接依赖 go
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd 间接依赖 go
cliui 7.0.4 间接依赖 npm
esquery 1.4.0 间接依赖 npm
has-flag 4.0.0 间接依赖 npm
k8s.io/klog/v2 v2.80.1 间接依赖 go
eslint 8.4.1 直接依赖 npm
import-fresh 3.3.0 间接依赖 npm
github.com/stretchr/testify v1.7.0 直接依赖 go
golang.org/x/text v0.5.0 间接依赖 go
gopkg.in/yaml.v2 v2.4.0 间接依赖 go
espree 9.2.0 间接依赖 npm
k8s.io/client-go v0.26.0 直接依赖 go
is-glob 4.0.1 间接依赖 npm
github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d 间接依赖 go
github.com/go-openapi/jsonpointer v0.19.3 间接依赖 go
assert-plus 1.0.0 间接依赖 npm
estraverse 5.3.0 间接依赖 npm
indent-string 4.0.0 间接依赖 npm
github.com/nats-io/jwt/v2 v2.5.2 间接依赖 go
regexpp 3.2.0 间接依赖 npm
strip-ansi 4.0.0 间接依赖 npm
json-stable-stringify-without-jsonify 1.0.1 间接依赖 npm
string-width 2.1.1 间接依赖 npm
golang.org/x/net v0.8.0 间接依赖 go
fast-json-stable-stringify 2.1.0 间接依赖 npm
github.com/kelseyhightower/envconfig v1.4.0 直接依赖 go
github.com/shopspring/decimal v1.2.0 间接依赖 go
github.com/json-iterator/go v1.1.8 间接依赖 go
golang.org/x/oauth2 v0.13.0 直接依赖 go
emoji-regex 8.0.0 直接依赖 npm
github.com/go-logr/logr v1.2.4 间接依赖 go
github.com/google/gofuzz v1.1.0 间接依赖 go
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 间接依赖 go
k8s.io/klog/v2 v2.5.0 直接依赖 go
form-data 2.5.1 间接依赖 npm
flatted 3.2.4 间接依赖 npm
github.com/google/gnostic v0.5.7-v3refs 间接依赖 go
github.com/nats-io/nats.go v1.31.0 直接依赖 go
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c 间接依赖 go
eslint-config-google 0.14.0 直接依赖 npm
moment 2.29.4 直接依赖 npm
github.com/Masterminds/sprig/v3 v3.2.2 间接依赖 go
github.com/bmizerany/assert v0.0.0-20160611221934-b7ed37b82869 直接依赖 go
github.com/json-iterator/go v1.1.12 间接依赖 go
github.com/go-openapi/jsonpointer v0.19.6 间接依赖 go
cross-spawn 7.0.3 间接依赖 npm
sigs.k8s.io/yaml v1.2.0 间接依赖 go
is-typedarray 1.0.0 间接依赖 npm
github.com/kyma-incubator/compass/components/director v0.0.0-20220126084901-92232f5eced0 直接依赖 go
k8s.io/code-generator v0.18.6 直接依赖 go
github.com/kyma-project/kyma/common/logging v0.0.0-20230130154909-4c81ab2cee61 直接依赖 go
mimic-response 1.0.1 间接依赖 npm
eslint-scope 7.1.0 间接依赖 npm
serialize-javascript 5.0.1 间接依赖 npm
golang.org/x/net v0.3.1-0.20221206200815-1e63c2f08a10 间接依赖 go
uuid 8.3.2 间接依赖 npm
forever-agent 0.6.1 间接依赖 npm
har-validator 5.1.5 间接依赖 npm
github.com/onsi/gomega v1.28.1 直接依赖 go
acorn-jsx 5.3.2 间接依赖 npm
js-yaml 4.1.0 间接依赖 npm
go.uber.org/multierr v1.6.0 间接依赖 go
@types/js-yaml 4.0.3 间接依赖 npm
is-core-module 2.2.0 间接依赖 npm
fs.realpath 1.0.0 间接依赖 npm
github.com/emicklei/go-restful/v3 v3.9.0 间接依赖 go
github.com/kyma-project/kyma/components/application-operator v0.0.0-20230127165033-ec8e43477eca 直接依赖 go
gomodules.xyz/jsonpatch/v2 v2.2.0 间接依赖 go
wide-align 1.1.3 间接依赖 npm
github.com/prometheus/procfs v0.11.1 间接依赖 go
golang.org/x/sys v0.3.0 间接依赖 go
ecc-jsbn 0.1.2 间接依赖 npm
github.com/go-logr/logr v1.3.0 直接依赖 go
asap 2.0.6 间接依赖 npm
github.com/gorilla/mux v1.8.0 直接依赖 go
github.com/modern-go/reflect2 v1.0.2 间接依赖 go
golang.org/x/tools v0.9.3 间接依赖 go
picomatch 2.3.1 间接依赖 npm
@types/underscore 1.10.24 间接依赖 npm
shebang-command 2.0.0 间接依赖 npm
github.com/onsi/ginkgo/v2 v2.11.0 直接依赖 go
aws4 1.11.0 间接依赖 npm
utf-8-validate 5.0.5 间接依赖 npm
gopkg.in/inf.v0 v0.9.1 间接依赖 go
golang.org/x/term v0.13.0 间接依赖 go
k8s.io/apimachinery v0.28.3 直接依赖 go
resolve 1.19.0 间接依赖 npm
github.com/nats-io/nkeys v0.4.5 间接依赖 go
github.com/kyma-project/kyma/components/compass-runtime-agent v0.0.0-20220927112044-a548531152a1 直接依赖 go
lowercase-keys 2.0.0 间接依赖 npm
github.com/google/gnostic-models v0.6.8 间接依赖 go
glob-parent 5.1.2 间接依赖 npm
github.com/matryer/is v1.4.0 直接依赖 go
github.com/Masterminds/goutils v1.1.1 间接依赖 go
extend 3.0.2 间接依赖 npm
minimatch 3.0.4 间接依赖 npm
github.com/kr/pretty v0.1.0 间接依赖 go
github.com/google/go-cmp v0.6.0 间接依赖 go
@types/minipass 2.2.0 间接依赖 npm
github.com/go-openapi/jsonreference v0.20.0 间接依赖 go
k8s.io/api v0.28.3 直接依赖 go
type 1.2.0 间接依赖 npm
gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b 间接依赖 go
doctrine 3.0.0 间接依赖 npm
responselike 2.0.0 间接依赖 npm
tmp-promise 3.0.2 间接依赖 npm
github.com/go-logr/zapr v1.2.4 直接依赖 go
tslib 1.14.1 间接依赖 npm
github.com/cespare/xxhash/v2 v2.2.0 间接依赖 go
github.com/mailru/easyjson v0.7.6 间接依赖 go
nanoid 3.1.20 间接依赖 npm
@types/node 10.17.49 间接依赖 npm
brace-expansion 1.1.11 间接依赖 npm
supports-color 8.1.1 间接依赖 npm
github.com/kyma-project/kyma/common/logging v0.0.0-20231025103331-ecda502ad878 直接依赖 go
quick-lru 5.1.1 间接依赖 npm
json-stringify-safe 5.0.1 间接依赖 npm
has 1.0.3 间接依赖 npm
isomorphic-ws 4.0.1 间接依赖 npm
go.uber.org/atomic v1.7.0 间接依赖 go
http2-wrapper 1.0.0-beta.5.2 间接依赖 npm
eslint-visitor-keys 3.1.0 间接依赖 npm
github.com/mitchellh/hashstructure/v2 v2.0.2 直接依赖 go
chalk 4.1.0 间接依赖 npm
p-cancelable 2.0.0 间接依赖 npm
dashdash 1.14.1 间接依赖 npm
mkdirp 1.0.4 间接依赖 npm
k8s.io/client-go v0.27.4 直接依赖 go
underscore 1.13.1 间接依赖 npm
ansi-regex 3.0.1 间接依赖 npm
optionator 0.9.1 间接依赖 npm
k8s.io/client-go v0.26.7 直接依赖 go
k8s.io/apiextensions-apiserver v0.28.3 间接依赖 go
golang.org/x/text v0.6.0 间接依赖 go
signal-exit 3.0.3 间接依赖 npm
sigs.k8s.io/json v0.0.0-20220713155537-f223a00ba0e2 间接依赖 go
glob 7.1.6 间接依赖 npm
@eslint/eslintrc 1.0.5 间接依赖 npm
github.com/josharian/intern v1.0.0 间接依赖 go
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 间接依赖 go
escape-string-regexp 4.0.0 间接依赖 npm
sigs.k8s.io/controller-runtime v0.16.3 直接依赖 go
@szmarczak/http-timer 4.0.5 间接依赖 npm
next-tick 1.0.0 间接依赖 npm
color-name 1.1.4 间接依赖 npm
gopkg.in/yaml.v2 v2.2.8 间接依赖 go
golang.org/x/net v0.17.0 间接依赖 go
jsbn 0.1.1 间接依赖 npm
safe-buffer 5.2.1 间接依赖 npm
github.com/google/uuid v1.3.0 直接依赖 go
argparse 2.0.1 间接依赖 npm
merge-stream 2.0.0 间接依赖 npm
asynckit 0.4.0 间接依赖 npm
k8s.io/component-base v0.26.1 间接依赖 go
shelljs 0.8.5 间接依赖 npm
go.uber.org/zap v1.25.0 直接依赖 go
fs-minipass 2.1.0 间接依赖 npm
yocto-queue 0.1.0 间接依赖 npm
yargs 16.2.0 间接依赖 npm
core-util-is 1.0.2 间接依赖 npm
github.com/kyma-project/api-gateway v0.0.0-20231025094533-b7f4433b5cac 直接依赖 go
github.com/golang/protobuf v1.5.3 间接依赖 go
github.com/patrickmn/go-cache v2.1.0+incompatible 直接依赖 go
npm-run-path 4.0.1 间接依赖 npm
ansi-styles 4.3.0 间接依赖 npm
wrappy 1.0.2 间接依赖 npm
yaeti 0.0.6 间接依赖 npm
github.com/prometheus/common v0.44.0 间接依赖 go
flat-cache 3.0.4 间接依赖 npm
github.com/gogo/protobuf v1.3.2 间接依赖 go
diff 5.0.0 间接依赖 npm
github.com/google/pprof v0.0.0-20210720184732-4bb14d4b1be1 间接依赖 go
github.com/go-logr/logr v1.2.3 间接依赖 go
get-func-name 2.0.0 间接依赖 npm
browser-or-node 2.1.1 间接依赖 npm
progress 2.0.3 间接依赖 npm
once 1.4.0 间接依赖 npm
k8s.io/kube-openapi v0.0.0-20230501164219-8b0f38b5fd1f 间接依赖 go
isexe 2.0.0 间接依赖 npm
aggregate-error 3.1.0 间接依赖 npm
deep-eql 3.0.1 间接依赖 npm
oidc-token-hash 5.0.0 间接依赖 npm
github.com/spf13/pflag v1.0.5 间接依赖 go
decompress-response 6.0.0 间接依赖 npm
go.uber.org/zap v1.24.0 直接依赖 go
@types/tar 4.0.4 间接依赖 npm
mocha-junit-reporter 2.0.0 直接依赖 npm
eslint-utils 3.0.0 间接依赖 npm
decamelize 4.0.0 间接依赖 npm
github.com/go-openapi/swag v0.19.5 间接依赖 go
base64url 3.0.1 间接依赖 npm
golang.org/x/sys v0.13.0 间接依赖 go
github.com/mailru/easyjson v0.7.0 间接依赖 go
verror 1.10.0 间接依赖 npm
github.com/google/gofuzz v1.2.0 间接依赖 go
sigs.k8s.io/structured-merge-diff/v4 v4.3.0 间接依赖 go
github.com/prometheus/client_model v0.3.0 间接依赖 go
getpass 0.1.7 间接依赖 npm
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 间接依赖 go
d 1.0.1 间接依赖 npm
github.com/nats-io/nuid v1.0.1 间接依赖 go
k8s.io/klog/v2 v2.90.1 间接依赖 go
concat-map 0.0.1 间接依赖 npm
acorn 8.6.0 间接依赖 npm
strip-json-comments 3.1.1 间接依赖 npm
resolve-from 4.0.0 间接依赖 npm
k8s.io/component-base v0.28.3 间接依赖 go
github.com/vektah/gqlparser/v2 v2.1.0 间接依赖 go
ext 1.5.0 间接依赖 npm
yargs-parser 20.2.4 间接依赖 npm
github.com/PuerkitoBio/purell v1.1.1 间接依赖 go
github.com/onsi/gomega v1.27.8 直接依赖 go
q 2.0.3 间接依赖 npm
github.com/go-openapi/jsonpointer v0.19.5 间接依赖 go
y18n 5.0.5 间接依赖 npm
github.com/golang/protobuf v1.5.2 间接依赖 go
github.com/pkg/errors v0.9.1 直接依赖 go
functional-red-black-tree 1.0.1 间接依赖 npm
request 2.88.2 间接依赖 npm
github.com/emicklei/go-restful v2.16.0+incompatible 间接依赖 go
node-gyp-build 4.2.3 间接依赖 npm
@types/request 2.48.5 间接依赖 npm
github.com/avast/retry-go v2.2.0+incompatible 直接依赖 go
performance-now 2.1.0 间接依赖 npm
@types/ws 6.0.4 间接依赖 npm
minimist 1.2.7 直接依赖 npm
braces 3.0.2 间接依赖 npm
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 间接依赖 go
go.opencensus.io v0.24.0 直接依赖 go
@types/stream-buffers 3.0.3 间接依赖 npm
github.com/machinebox/graphql v0.2.3-0.20181106130121-3a9253180225 直接依赖 go
github.com/rogpeppe/go-internal v1.11.0 间接依赖 go
randombytes 2.1.0 间接依赖 npm
google.golang.org/protobuf v1.31.0 间接依赖 go
github.com/nats-io/nats-server/v2 v2.10.3 直接依赖 go
fast-levenshtein 2.0.6 间接依赖 npm
@humanwhocodes/object-schema 1.2.1 间接依赖 npm
json-schema-traverse 0.4.1 间接依赖 npm
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 间接依赖 go
tmp 0.2.1 间接依赖 npm
github.com/kr/text v0.1.0 间接依赖 go
cacheable-lookup 5.0.4 间接依赖 npm
golang.org/x/text v0.13.0 间接依赖 go
anymatch 3.1.2 间接依赖 npm
mocha 8.3.2 直接依赖 npm
tar 6.0.5 间接依赖 npm
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb 间接依赖 go
k8s.io/kube-openapi v0.0.0-20221012153701-172d655c2280 间接依赖 go
aws-sign2 0.7.0 间接依赖 npm
github.com/go-openapi/spec v0.19.3 间接依赖 go
safer-buffer 2.1.2 间接依赖 npm
github.com/cloudevents/sdk-go/v2 v2.14.0 直接依赖 go
github.com/evanphx/json-patch v4.12.0+incompatible 间接依赖 go
k8s.io/metrics v0.26.7 直接依赖 go
@types/cacheable-request 6.0.1 间接依赖 npm
word-wrap 1.2.3 间接依赖 npm
github.com/huandu/xstrings v1.3.2 间接依赖 go
strip-final-newline 2.0.0 间接依赖 npm
typedarray-to-buffer 3.1.5 间接依赖 npm
k8s.io/client-go v0.28.3 直接依赖 go
binary-extensions 2.2.0 间接依赖 npm
k8s.io/klog/v2 v2.100.1 间接依赖 go
github.com/evanphx/json-patch/v5 v5.6.0 间接依赖 go
onetime 5.1.2 间接依赖 npm
path-exists 4.0.0 间接依赖 npm
github.com/xeipuuv/gojsonschema v1.2.0 间接依赖 go
golang.org/x/term v0.4.0 间接依赖 go
is-stream 2.0.0 间接依赖 npm
p-limit 3.1.0 间接依赖 npm
@types/tough-cookie 4.0.0 间接依赖 npm
node-forge 0.10.0 直接依赖 npm
oauth-sign 0.9.0 间接依赖 npm
get-caller-file 2.0.5 间接依赖 npm
github.com/go-http-utils/logger v0.0.0-20161128092850-f3a42dcdeae6 直接依赖 go
mime-types 2.1.27 间接依赖 npm
@types/http-cache-semantics 4.0.0 间接依赖 npm
github.com/fsnotify/fsnotify v1.6.0 间接依赖 go
deep-is 0.1.4 间接依赖 npm
assertion-error 1.1.0 间接依赖 npm
object-hash 2.0.3 间接依赖 npm
byline 5.0.0 间接依赖 npm
github.com/stretchr/testify v1.8.4 直接依赖 go
github.com/go-openapi/jsonreference v0.20.2 间接依赖 go
github.com/mitchellh/copystructure v1.1.2 间接依赖 go
log-symbols 4.0.0 间接依赖 npm
github.com/pmezard/go-difflib v1.0.0 间接依赖 go
github.com/hashicorp/errwrap v1.1.0 间接依赖 go
http-cache-semantics 4.1.0 直接依赖 npm
github.com/evanphx/json-patch v5.6.0+incompatible 间接依赖 go
camelcase 6.2.0 间接依赖 npm
github.com/google/go-cmp v0.3.1 间接依赖 go
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4 间接依赖 go
fsevents 2.3.2 间接依赖 npm
google.golang.org/appengine v1.6.7 间接依赖 go
@humanwhocodes/config-array 0.9.2 间接依赖 npm
psl 1.8.0 间接依赖 npm
resolve-alpn 1.0.0 间接依赖 npm
@ungap/promise-all-settled 1.1.2 间接依赖 npm
p-locate 5.0.0 间接依赖 npm
pump 3.0.0 直接依赖 npm
jsprim 1.4.1 间接依赖 npm
gomodules.xyz/jsonpatch/v2 v2.4.0 间接依赖 go
stream-buffers 3.0.2 间接依赖 npm
github.com/go-openapi/swag v0.19.15 间接依赖 go
tweetnacl 0.14.5 间接依赖 npm
execa 5.0.0 间接依赖 npm
github.com/matttproud/golang_protobuf_extensions v1.0.4 间接依赖 go
k8s.io/utils v0.0.0-20230726121419-3b25d923346b 直接依赖 go
which 2.0.2 间接依赖 npm
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
github.com/cespare/xxhash/v2 v2.1.2 间接依赖 go
shebang-regex 3.0.0 间接依赖 npm
v8-compile-cache 2.3.0 间接依赖 npm
github.com/onsi/ginkgo v1.16.5 直接依赖 go
@sindresorhus/is 4.0.0 间接依赖 npm
golang.org/x/exp v0.0.0-20230905200255-921286631fa9 间接依赖 go
rimraf 3.0.2 间接依赖 npm
weak-map 1.0.5 间接依赖 npm
path-parse 1.0.6 间接依赖 npm
sshpk 1.16.1 间接依赖 npm
pop-iterate 1.0.1 间接依赖 npm
follow-redirects 1.13.1 间接依赖 npm
combined-stream 1.0.8 间接依赖 npm
github.com/kyma-project/kyma/components/central-application-gateway v0.0.0-20230201152417-102edd243eab 直接依赖 go
workerpool 6.1.0 间接依赖 npm
github.com/sirupsen/logrus v1.9.0 直接依赖 go
github.com/prometheus/client_golang v1.17.0 直接依赖 go
fast-deep-equal 3.1.3 间接依赖 npm
k8s.io/klog v1.0.0 间接依赖 go
github.com/avast/retry-go/v3 v3.1.1 直接依赖 go
ignore 4.0.6 间接依赖 npm
golang.org/x/time v0.3.0 间接依赖 go
jose 2.0.6 间接依赖 npm
github.com/oklog/run v1.1.0 直接依赖 go
github.com/mailru/easyjson v0.7.7 间接依赖 go
github.com/matttproud/golang_protobuf_extensions v1.0.2 间接依赖 go
github.com/cloudevents/sdk-go/protocol/nats/v2 v2.14.0 直接依赖 go
axios 0.21.1 直接依赖 npm
google.golang.org/protobuf v1.28.1 间接依赖 go
github.com/nxadm/tail v1.4.8 间接依赖 go
github.com/sirupsen/logrus v1.9.3 直接依赖 go
json-buffer 3.0.1 间接依赖 npm
go.uber.org/multierr v1.10.0 间接依赖 go
es6-symbol 3.1.3 间接依赖 npm
file-entry-cache 6.0.1 间接依赖 npm
github.com/stretchr/testify v1.8.1 直接依赖 go
asn1 0.2.4 间接依赖 npm
minipass 3.1.3 间接依赖 npm
he 1.2.0 间接依赖 npm
is-number 7.0.0 间接依赖 npm
yallist 4.0.0 间接依赖 npm
keyv 4.0.3 直接依赖 npm
chokidar 3.5.1 间接依赖 npm
text-table 0.2.0 间接依赖 npm
prelude-ls 1.2.1 间接依赖 npm
chai 4.2.0 直接依赖 npm
github.com/minio/highwayhash v1.0.2 间接依赖 go
xml 1.0.1 间接依赖 npm
chownr 2.0.0 间接依赖 npm
yargs-unparser 2.0.0 间接依赖 npm
human-signals 2.1.0 间接依赖 npm
github.com/modern-go/reflect2 v1.0.1 间接依赖 go
locate-path 6.0.0 间接依赖 npm
k8s.io/api v0.27.4 直接依赖 go
esutils 2.0.3 间接依赖 npm
github.com/agnivade/levenshtein v1.1.0 间接依赖 go
p-some 5.0.0 间接依赖 npm
golang.org/x/mod v0.7.0 间接依赖 go
github.com/99designs/gqlgen v0.11.3 间接依赖 go
rechoir 0.6.2 间接依赖 npm
k8s.io/apiextensions-apiserver v0.26.1 间接依赖 go
k8s.io/api v0.26.0 直接依赖 go
github.com/kyma-incubator/compass/components/connector v0.0.0-20220104122431-99ed924ea212 直接依赖 go
json-schema 0.2.3 间接依赖 npm
github.com/avast/retry-go v3.0.0+incompatible 直接依赖 go
github.com/prometheus/procfs v0.8.0 间接依赖 go
@types/responselike 1.0.0 间接依赖 npm
bufferutil 4.0.3 间接依赖 npm
is-buffer 1.1.6 间接依赖 npm
path-key 3.1.1 间接依赖 npm
readdirp 3.5.0 间接依赖 npm
@types/caseless 0.12.2 间接依赖 npm
charenc 0.0.2 间接依赖 npm
color-convert 2.0.1 间接依赖 npm
(0)
上一篇 2023年11月1日
下一篇 2023年11月1日

相关推荐

  • deepkit/deepkit-framework 软件分析报告

    基础信息 项目名称:deepkit/deepkit-framework 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1717106854709739520/1717106855565377536 此报告由Murp…

    软件分析 2023年10月25日
    0
  • cnguu/vuepress-theme-yur 软件分析报告

    基础信息 项目名称:cnguu/vuepress-theme-yur 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716755217440882688/1716755217495408640 此报告由Murph…

    软件分析 2023年10月24日
    0
  • pqina/filepond 软件分析报告

    基础信息 项目名称:pqina/filepond 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1755986057779286016/1755986057817034752 此报告由Murphysec提供 漏洞列…

    软件分析 2024年2月10日
    0
  • atom/teletype 软件分析报告

    基础信息 项目名称:atom/teletype 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716106388098039808/1716106390128082944 此报告由Murphysec提供 漏洞列表…

    软件分析 2023年10月23日
    0
  • yandeu/phaser-project-template 软件分析报告

    基础信息 项目名称:yandeu/phaser-project-template 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721637936523710465/1721637936569847808 此报告…

    软件分析 2023年11月7日
    0