Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all):
- dependency-check version: 12.2.0
- Report Generated On: Wed, 25 Mar 2026 17:22:42 +0100
- Dependencies Scanned: 23 (12 unique)
- Vulnerable Dependencies: 0
- Vulnerabilities Found: 0
- Vulnerabilities Suppressed: 0
- ...
- NVD API Last Checked: 2026-03-25T16:57:47+01
- NVD API Last Modified: 2026-03-25T15:47:08Z
Summary
Summary of Vulnerable Dependencies (click to show all)
@borewit/text-codec:0.1.1
Description:
Text Decoder
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/token-types:6.1.1/@borewit/text-codec:^0.1.0
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16
- @dpuse/dpuse-tool-file-operators:0.0.16/token-types:6.1.1
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author.name | Borewit | Highest |
| Vendor | package.json | author.url | https://github.com/Borewit | Highest |
| Vendor | package.json | description | Text Decoder | Highest |
| Vendor | package.json | name | @borewit/text-codec | Highest |
| Vendor | package.json | name | @borewit/text-codec_project | Highest |
| Product | package.json | name | @borewit/text-codec | Highest |
| Version | package.json | version | 0.1.1 | Highest |
Related Dependencies
- @borewit/text-codec:0.1.1
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/@borewit/text-codec:0.1.1
- pkg:npm/%40borewit%2Ftext-codec@0.1.1
- pkg:npm/%40borewit%2Ftext-codec@0.1.1
(Confidence:Highest)
@dpuse/dpuse-shared:0.3.595
Description:
Common constants, types and utilities used across all DPUse projects.
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/@dpuse/dpuse-shared:0.3.595
Referenced In Project/Scope: @dpuse/dpuse-tool-file-operators:0.0.16
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author | Jonathan Terrell <terrell.jm@gmail.com> | Highest |
| Vendor | package.json | bugs.url | https://github.com/data-positioning/dpuse-shared/issues | Highest |
| Vendor | package.json | description | Common constants, types and utilities used across all DPUse projects. | Highest |
| Vendor | package.json | homepage | https://www.dpuse.app | Highest |
| Vendor | package.json | name | @dpuse/dpuse-shared | Highest |
| Vendor | package.json | name | @dpuse/dpuse-shared_project | Highest |
| Product | package.json | name | @dpuse/dpuse-shared | Highest |
| Version | package.json | version | 0.3.595 | Highest |
- pkg:npm/%40dpuse%2Fdpuse-shared@0.3.595
(Confidence:Highest)
@tokenizer/inflate:0.4.1
Description:
Tokenized zip support
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/file-type:21.3.4/@tokenizer/inflate:^0.4.1
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16/file-type:21.3.4
- @dpuse/dpuse-tool-file-operators:0.0.16
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author.name | Borewit | Highest |
| Vendor | package.json | author.url | https://github.com/Borewit | Highest |
| Vendor | package.json | bugs.url | hhttps://github.com/Borewit/tokenizer-inflate/issues | Highest |
| Vendor | package.json | description | Tokenized zip support | Highest |
| Vendor | package.json | name | @tokenizer/inflate | Highest |
| Vendor | package.json | name | @tokenizer/inflate_project | Highest |
| Product | package.json | name | @tokenizer/inflate | Highest |
| Version | package.json | version | 0.4.1 | Highest |
Related Dependencies
- @tokenizer/inflate:0.4.1
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/@tokenizer/inflate:0.4.1
- pkg:npm/%40tokenizer%2Finflate@0.4.1
- pkg:npm/%40tokenizer%2Finflate@0.4.1
(Confidence:Highest)
@tokenizer/token:0.3.0
Description:
TypeScript definition for strtok3 token
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/token-types:6.1.1/@tokenizer/token:^0.3.0
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16/strtok3:10.3.4
- @dpuse/dpuse-tool-file-operators:0.0.16
- @dpuse/dpuse-tool-file-operators:0.0.16/token-types:6.1.1
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author.name | Borewit | Highest |
| Vendor | package.json | author.url | https://github.com/Borewit | Highest |
| Vendor | package.json | bugs.url | https://github.com/Borewit/tokenizer-token/issues | Highest |
| Vendor | package.json | description | TypeScript definition for strtok3 token | Highest |
| Vendor | package.json | name | @tokenizer/token | Highest |
| Vendor | package.json | name | @tokenizer/token_project | Highest |
| Product | package.json | name | @tokenizer/token | Highest |
| Version | package.json | version | 0.3.0 | Highest |
Related Dependencies
- @tokenizer/token:0.3.0
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/@tokenizer/token:0.3.0
- pkg:npm/%40tokenizer%2Ftoken@0.3.0
- @tokenizer/token:0.3.0
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/strtok3:10.3.4/@tokenizer/token:^0.3.0
- pkg:npm/%40tokenizer%2Ftoken@0.3.0
- pkg:npm/%40tokenizer%2Ftoken@0.3.0
(Confidence:Highest)
chardet:2.1.1
Description:
Character encoding detector
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/chardet:2.1.1
Referenced In Project/Scope: @dpuse/dpuse-tool-file-operators:0.0.16
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author | Dmitry Shirokov <deadrunk@gmail.com> | Highest |
| Vendor | package.json | bugs.mail | deadrunk@gmail.com | Highest |
| Vendor | package.json | bugs.url | http://github.com/runk/node-chardet/issues | Highest |
| Vendor | package.json | description | Character encoding detector | Highest |
| Vendor | package.json | homepage | https://github.com/runk/node-chardet | Highest |
| Vendor | package.json | name | chardet | Highest |
| Vendor | package.json | name | chardet_project | Highest |
| Product | package.json | name | chardet | Highest |
| Version | package.json | version | 2.1.1 | Highest |
- pkg:npm/chardet@2.1.1
(Confidence:Highest)
debug:4.4.3
Description:
Lightweight debugging utility for Node.js and the browser
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/debug:4.4.3
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16/@tokenizer/inflate:0.4.1
- @dpuse/dpuse-tool-file-operators:0.0.16
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author | Josh Junon (https://github.com/qix-) | Highest |
| Vendor | package.json | description | Lightweight debugging utility for Node.js and the browser | Highest |
| Vendor | package.json | name | debug | Highest |
| Vendor | package.json | name | debug_project | Highest |
| Product | package.json | name | debug | Highest |
| Version | package.json | version | 4.4.3 | Highest |
Related Dependencies
- debug:4.4.3
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/@tokenizer/inflate:0.4.1/debug:^4.4.3
- pkg:npm/debug@4.4.3
file-type:21.3.4
Description:
Detect the file type of a file, stream, or data
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/file-type:21.3.4
Referenced In Project/Scope: @dpuse/dpuse-tool-file-operators:0.0.16
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author.email | sindresorhus@gmail.com | Highest |
| Vendor | package.json | author.name | Sindre Sorhus | Highest |
| Vendor | package.json | author.url | https://sindresorhus.com | Highest |
| Vendor | package.json | description | Detect the file type of a file, stream, or data | Highest |
| Vendor | package.json | name | file-type | Highest |
| Vendor | package.json | name | file-type_project | Highest |
| Product | package.json | name | file-type | Highest |
| Version | package.json | version | 21.3.4 | Highest |
ieee754:1.2.1
Description:
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
License:
BSD-3-Clause
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/token-types:6.1.1/ieee754:^1.2.1
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16
- @dpuse/dpuse-tool-file-operators:0.0.16/token-types:6.1.1
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author.email | feross@feross.org | Highest |
| Vendor | package.json | author.name | Feross Aboukhadijeh | Highest |
| Vendor | package.json | author.url | https://feross.org | Highest |
| Vendor | package.json | description | Read/write IEEE754 floating point numbers from/to a Buffer or array-like object | Highest |
| Vendor | package.json | name | ieee754 | Highest |
| Vendor | package.json | name | ieee754_project | Highest |
| Product | package.json | name | ieee754 | Highest |
| Version | package.json | version | 1.2.1 | Highest |
Related Dependencies
- ieee754:1.2.1
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/ieee754:1.2.1
- pkg:npm/ieee754@1.2.1
- pkg:npm/ieee754@1.2.1
(Confidence:Highest)
ms:2.1.3
Description:
Tiny millisecond conversion utility
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/ms:2.1.3
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16
- @dpuse/dpuse-tool-file-operators:0.0.16/debug:4.4.3
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | description | Tiny millisecond conversion utility | Highest |
| Vendor | package.json | name | ms | Highest |
| Vendor | package.json | name | ms_project | Highest |
| Product | package.json | name | ms | Highest |
| Version | package.json | version | 2.1.3 | Highest |
Related Dependencies
- ms:2.1.3
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/debug:4.4.3/ms:^2.1.3
- pkg:npm/ms@2.1.3
- pkg:npm/ms@2.1.3
(Confidence:Highest)
strtok3:10.3.4
Description:
A promise based streaming tokenizer
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/strtok3:10.3.4
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16/file-type:21.3.4
- @dpuse/dpuse-tool-file-operators:0.0.16
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author.name | Borewit | Highest |
| Vendor | package.json | author.url | https://github.com/Borewit | Highest |
| Vendor | package.json | bugs.url | https://github.com/Borewit/strtok3/issues | Highest |
| Vendor | package.json | description | A promise based streaming tokenizer | Highest |
| Vendor | package.json | name | strtok3 | Highest |
| Vendor | package.json | name | strtok3_project | Highest |
| Product | package.json | name | strtok3 | Highest |
| Version | package.json | version | 10.3.4 | Highest |
Related Dependencies
- strtok3:10.3.4
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/file-type:21.3.4/strtok3:^10.3.4
- pkg:npm/strtok3@10.3.4
- pkg:npm/strtok3@10.3.4
(Confidence:Highest)
token-types:6.1.1
Description:
Common token types for decoding and encoding numeric and string values
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/token-types:6.1.1
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16/file-type:21.3.4
- @dpuse/dpuse-tool-file-operators:0.0.16/@tokenizer/inflate:0.4.1
- @dpuse/dpuse-tool-file-operators:0.0.16
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author.name | Borewit | Highest |
| Vendor | package.json | author.url | https://github.com/Borewit | Highest |
| Vendor | package.json | bugs.url | https://github.com/Borewit/token-types/issues | Highest |
| Vendor | package.json | description | Common token types for decoding and encoding numeric and string values | Highest |
| Vendor | package.json | name | token-types | Highest |
| Vendor | package.json | name | token-types_project | Highest |
| Product | package.json | name | token-types | Highest |
| Version | package.json | version | 6.1.1 | Highest |
Related Dependencies
- token-types:6.1.1
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/@tokenizer/inflate:0.4.1/token-types:^6.1.1
- pkg:npm/token-types@6.1.1
- token-types:6.1.1
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/file-type:21.3.4/token-types:^6.1.1
- pkg:npm/token-types@6.1.1
- pkg:npm/token-types@6.1.1
(Confidence:Highest)
uint8array-extras:1.5.0
Description:
Useful utilities for working with Uint8Array (and Buffer)
License:
MIT
File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/uint8array-extras:1.5.0
Referenced In Projects/Scopes:
- @dpuse/dpuse-tool-file-operators:0.0.16/file-type:21.3.4
- @dpuse/dpuse-tool-file-operators:0.0.16
Evidence
| Type | Source | Name | Value | Confidence |
| Vendor | package.json | author.email | sindresorhus@gmail.com | Highest |
| Vendor | package.json | author.name | Sindre Sorhus | Highest |
| Vendor | package.json | author.url | https://sindresorhus.com | Highest |
| Vendor | package.json | description | Useful utilities for working with Uint8Array (and Buffer) | Highest |
| Vendor | package.json | name | uint8array-extras | Highest |
| Vendor | package.json | name | uint8array-extras_project | Highest |
| Product | package.json | name | uint8array-extras | Highest |
| Version | package.json | version | 1.5.0 | Highest |
Related Dependencies
- uint8array-extras:1.5.0
- File Path: /Users/jonathanterrell/DPUse/GitHub/tools/dpuse-tool-file-operators/package-lock.json?dpuse-tool-file-operators:0.0.16/file-type:21.3.4/uint8array-extras:^1.4.0
- pkg:npm/uint8array-extras@1.5.0
- pkg:npm/uint8array-extras@1.5.0
(Confidence:Highest)