arduino/arduino-cli 软件分析报告

基础信息

项目名称:arduino/arduino-cli

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1725082059997143040/1725082060286550016

此报告由Murphysec提供

漏洞列表

暂无

缺陷组件

暂无

许可证风险

许可证类型 相关组件 许可证风险
MIT 79
BSD-3-Clause 29
GPL-2.0 4
ISC 15
Apache-2.0 18
BSD-2-Clause 12
MPL-2.0 3
LGPL-2.1 1
GPL-3.0 2
Python-2.0 1
LGPL-3.0 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
github.com/subosito/gotenv v1.6.0 间接依赖 go
get-stdin 9.0.0 间接依赖 npm
github.com/josharian/intern v1.0.0 间接依赖 go
html-link-extractor 1.0.5 间接依赖 npm
github.com/mitchellh/go-homedir v1.1.0 间接依赖 go
github.com/sagikazarmark/slog-shim v0.1.0 间接依赖 go
github.com/imdario/mergo v0.3.12 间接依赖 go
github.com/golang/protobuf v1.5.3 间接依赖 go
golang.org/x/term v0.14.0 直接依赖 go
github.com/rifflock/lfshook v0.0.0-20180920164130-b9218ef580f5 直接依赖 go
ms 2.1.3 间接依赖 npm
parse5-htmlparser2-tree-adapter 7.0.0 间接依赖 npm
ignore 5.2.4 间接依赖 npm
github.com/gofrs/uuid/v5 v5.0.0 直接依赖 go
github.com/mitchellh/mapstructure v1.5.0 间接依赖 go
github.com/arduino/go-properties-orderedmap v1.8.0 直接依赖 go
github.com/h2non/filetype v1.1.3 间接依赖 go
go.bug.st/serial v1.6.1 直接依赖 go
minimatch 5.1.6 间接依赖 npm
github.com/xanzy/ssh-agent v0.3.3 间接依赖 go
cheerio 1.0.0-rc.12 间接依赖 npm
gopkg.in/warnings.v0 v0.1.2 间接依赖 go
github.com/ulikunitz/xz v0.5.11 间接依赖 go
gopkg.in/yaml.v3 v3.0.1 直接依赖 go
github.com/sergi/go-diff v1.3.1 间接依赖 go
google.golang.org/grpc v1.59.0 直接依赖 go
parse5 7.1.2 间接依赖 npm
color-name 1.1.4 间接依赖 npm
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 间接依赖 go
cheerio-select 2.1.0 间接依赖 npm
deep-extend 0.6.0 间接依赖 npm
css-select 5.1.0 间接依赖 npm
github.com/hashicorp/hcl v1.0.0 间接依赖 go
github.com/pelletier/go-toml/v2 v2.1.0 间接依赖 go
uc.micro 1.0.6 间接依赖 npm
github.com/xeipuuv/gojsonschema v1.2.0 直接依赖 go
go.bug.st/cleanup v1.0.0 直接依赖 go
github.com/russross/blackfriday/v2 v2.1.0 间接依赖 go
github.com/djherbis/nio/v3 v3.0.1 直接依赖 go
github.com/fsnotify/fsnotify v1.6.0 间接依赖 go
fs.realpath 1.0.0 间接依赖 npm
inherits 2.0.4 间接依赖 npm
run-con 1.2.11 间接依赖 npm
github.com/arduino/go-win32-utils v1.0.0 直接依赖 go
punycode 2.3.0 间接依赖 npm
supports-color 7.2.0 间接依赖 npm
github.com/arduino/pluggable-monitor-protocol-handler v0.9.2 直接依赖 go
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 间接依赖 go
github.com/spf13/afero v1.10.0 间接依赖 go
github.com/schollz/closestmatch v2.1.0+incompatible 直接依赖 go
github.com/spf13/viper v1.17.0 直接依赖 go
ini 3.0.1 间接依赖 npm
github.com/mattn/go-colorable v0.1.13 直接依赖 go
github.com/arduino/pluggable-discovery-protocol-handler/v2 v2.1.1 直接依赖 go
github.com/rogpeppe/go-internal v1.11.0 直接依赖 go
github.com/codeclysm/extract/v3 v3.1.1 直接依赖 go
domhandler 5.0.3 间接依赖 npm
dom-serializer 2.0.0 间接依赖 npm
link-check 5.2.0 间接依赖 npm
js-yaml 4.1.0 间接依赖 npm
jsonc-parser 3.2.0 间接依赖 npm
github.com/sagikazarmark/locafero v0.3.0 间接依赖 go
golang.org/x/exp v0.0.0-20230905200255-921286631fa9 间接依赖 go
github.com/mattn/go-runewidth v0.0.15 间接依赖 go
golang.org/x/tools v0.13.0 间接依赖 go
domelementtype 2.3.0 间接依赖 npm
golang.org/x/text v0.14.0 直接依赖 go
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f 间接依赖 go
is-absolute-url 4.0.1 间接依赖 npm
css-what 6.1.0 间接依赖 npm
github.com/hashicorp/errwrap v1.0.0 间接依赖 go
linkify-it 4.0.1 间接依赖 npm
go.bug.st/downloader/v2 v2.1.1 直接依赖 go
golang.org/x/crypto v0.14.0 间接依赖 go
boolbase 1.0.0 间接依赖 npm
github.com/spf13/cobra v1.8.0 直接依赖 go
github.com/sirupsen/logrus v1.9.3 直接依赖 go
glob 8.0.3 间接依赖 npm
github.com/cyphar/filepath-securejoin v0.2.4 间接依赖 go
github.com/cmaglie/pb v1.0.27 直接依赖 go
ansi-styles 4.3.0 间接依赖 npm
domutils 3.0.1 间接依赖 npm
brace-expansion 2.0.1 间接依赖 npm
markdown-link-extractor 3.1.0 间接依赖 npm
github.com/spf13/cast v1.5.1 间接依赖 go
htmlparser2 8.0.1 间接依赖 npm
entities 4.4.0 间接依赖 npm
github.com/sourcegraph/conc v0.3.0 间接依赖 go
go.uber.org/atomic v1.9.0 间接依赖 go
github.com/stretchr/testify v1.8.4 直接依赖 go
github.com/kevinburke/ssh_config v1.2.0 间接依赖 go
golang.org/x/sys v0.14.0 间接依赖 go
tensorflow-lite 间接依赖
markdownlint 0.27.0 间接依赖 npm
markdownlint-cli 0.33.0 直接依赖 npm
minimist 1.2.8 间接依赖 npm
strip-json-comments 3.1.1 间接依赖 npm
argparse 2.0.1 间接依赖 npm
github.com/itchyny/gojq v0.12.8 间接依赖 go
has-flag 4.0.0 间接依赖 npm
github.com/hashicorp/go-multierror v1.1.1 间接依赖 go
github.com/acomagu/bufpipe v1.0.3 间接依赖 go
github.com/go-git/go-billy/v5 v5.5.0 间接依赖 go
mdurl 1.0.1 间接依赖 npm
inflight 1.0.6 间接依赖 npm
marked 4.2.12 间接依赖 npm
go.uber.org/multierr v1.9.0 间接依赖 go
github.com/Microsoft/go-winio v0.6.1 间接依赖 go
gemmlowp cci.20210928 间接依赖
github.com/inconshreveable/mousetrap v1.1.0 间接依赖 go
is-relative-url 4.0.0 间接依赖 npm
needle 3.2.0 间接依赖 npm
isemail 3.2.0 间接依赖 npm
github.com/fatih/color v1.16.0 直接依赖 go
github.com/ProtonMail/go-crypto v0.0.0-20230828082145-3c4c8a2d2371 直接依赖 go
go.bug.st/testifyjson v1.1.1 直接依赖 go
github.com/arduino/go-paths-helper v1.9.2 直接依赖 go
wrappy 1.0.2 间接依赖 npm
google.golang.org/protobuf v1.31.0 直接依赖 go
once 1.4.0 间接依赖 npm
github.com/leonelquinteros/gotext v1.4.0 直接依赖 go
github.com/mattn/go-isatty v0.0.20 直接依赖 go
tensorflow-lite 2.6.0 间接依赖
github.com/itchyny/timefmt-go v0.1.3 间接依赖 go
github.com/djherbis/buffer v1.2.0 直接依赖 go
github.com/emirpasic/gods v1.18.1 间接依赖 go
github.com/cpuguy83/go-md2man/v2 v2.0.3 间接依赖 go
commander 6.2.1 间接依赖 npm
github.com/arduino/go-timeutils v0.0.0-20171220113728-d1dd9e313b1b 直接依赖 go
github.com/spf13/pflag v1.0.5 间接依赖 go
gemmlowp 间接依赖
github.com/marcinbor85/gohex v0.0.0-20210308104911-55fb1c624d84 直接依赖 go
github.com/rivo/uniseg v0.4.4 间接依赖 go
color-convert 2.0.1 间接依赖 npm
github.com/juju/errors v1.0.0 间接依赖 go
github.com/klauspost/compress v1.17.0 间接依赖 go
github.com/mailru/easyjson v0.7.7 直接依赖 go
sax 1.2.4 间接依赖 npm
markdown-link-check 3.10.3 直接依赖 npm
go.bug.st/relaxed-semver v0.11.0 直接依赖 go
github.com/go-git/go-git/v5 v5.4.2 直接依赖 go
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 间接依赖 go
chalk 4.1.2 间接依赖 npm
debug 3.2.7 间接依赖 npm
github.com/magiconair/properties v1.8.7 间接依赖 go
google.golang.org/genproto/googleapis/rpc v0.0.0-20231012201019-e917dd12ba7a 直接依赖 go
async 3.2.4 间接依赖 npm
iconv-lite 0.6.3 间接依赖 npm
sigs.k8s.io/yaml v1.4.0 直接依赖 go
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 间接依赖 go
github.com/pkg/errors v0.9.1 直接依赖 go
balanced-match 1.0.2 间接依赖 npm
progress 2.0.3 间接依赖 npm
gopkg.in/ini.v1 v1.67.0 间接依赖 go
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc 间接依赖 go
lodash 4.17.21 间接依赖 npm
markdown-it 13.0.1 间接依赖 npm
github.com/creack/goselect v0.1.2 间接依赖 go
safer-buffer 2.1.2 间接依赖 npm
github.com/cloudflare/circl v1.3.3 间接依赖 go
golang.org/x/mod v0.12.0 间接依赖 go
golang.org/x/net v0.17.0 间接依赖 go
(0)
上一篇 2023年11月16日
下一篇 2023年11月16日

相关推荐

  • cazala/synaptic 软件分析报告

    基础信息 项目名称:cazala/synaptic 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716591442049941504/1716591442343542784 此报告由Murphysec提供 漏洞…

    软件分析 2023年10月24日
    0
  • apollographql/graphql-subscriptions 软件分析报告

    基础信息 项目名称:apollographql/graphql-subscriptions 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1715969486434910208/171596948654815641…

    软件分析 2023年10月23日
    0
  • iprignano/tendina 软件分析报告

    基础信息 项目名称:iprignano/tendina 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718866547664797696/1718866548138754048 此报告由Murphysec提供 …

    软件分析 2023年10月30日
    0
  • envygeeks/jekyll-assets 软件分析报告

    基础信息 项目名称:envygeeks/jekyll-assets 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721165317534646272/1730245011381379072 此报告由Murphy…

    软件分析 2023年11月30日
    0
  • coderliguoqing/vans 软件分析报告

    基础信息 项目名称:coderliguoqing/vans 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716778651697676288/1716778651798339584 此报告由Murphysec提…

    软件分析 2023年10月24日
    0