All logkitty versions

logkitty @0.6.1

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
43
Risk Score
MIT
License
No
Install Scripts
3
Dependencies
15
Dev Dependencies
26.7 KB
Package Size
Published

Display pretty Android and iOS logs without Android Studio or Console.app, with intuitive Command Line Interface.

Maintainers

zamotany

Keywords

logcatcliandroidandroid studioiosConsole.appconsoleloglogslogging

Dependencies (3)

PackageConstraintRegistry Status
dayjs ^1.8.15 auto_approved
yargs ^12.0.5 auto_approved
ansi-fragments ^0.2.1 auto_approved

Dev Dependencies (15)

PackageConstraintRegistry Status
jest ^24.7.1 auto_approved
eslint ^5.16.0 auto_approved
@babel/cli ^7.4.3 auto_approved
babel-jest ^24.7.1 auto_approved
typescript ^3.2.4 auto_approved
@babel/core ^7.4.3 auto_approved
@types/jest ^24.0.11 No greenflagged match
@types/node ^10.12.18 auto_approved
@types/yargs ^12.0.7 auto_approved
@babel/preset-env ^7.4.3 auto_approved
@babel/preset-typescript ^7.3.3 auto_approved
@callstack/eslint-config ^4.2.0 Not imported
@typescript-eslint/parser ^1.6.0 auto_approved
@typescript-eslint/eslint-plugin ^1.6.0 auto_approved
@babel/plugin-proposal-class-properties ^7.4.0 auto_approved

Transitive Dependency Tree

57 transitive deps max depth 8
  ├─ ansi-fragments ^0.2.1 → 0.2.1
  ├─ dayjs ^1.8.15 → 1.11.21
├─ yargs ^12.0.5 → 12.0.5
  ├─ cliui ^4.0.0 → 4.1.0
  ├─ colorette ^1.0.7 → 1.4.0
  ├─ decamelize ^1.2.0 → 1.2.0
  ├─ find-up ^3.0.0 → 3.0.0
  ├─ get-caller-file ^1.0.1
  ├─ os-locale ^3.0.0 → 3.1.0
  ├─ require-directory ^2.1.1 → 2.1.1
  ├─ require-main-filename ^1.0.1 → 1.0.1
  ├─ set-blocking ^2.0.0 → 2.0.0
  ├─ slice-ansi ^2.0.0 → 2.1.0
  ├─ string-width ^2.0.0 → 2.1.1
  ├─ strip-ansi ^5.0.0 → 5.2.0
  ├─ which-module ^2.0.0 → 2.0.1
  ├─ y18n ^3.2.1 || ^4.0.0
├─ yargs-parser ^11.1.1
  ├─ ansi-regex ^4.1.0 → 4.1.1
  ├─ ansi-styles ^3.2.0 → 3.2.1
  ├─ astral-regex ^1.0.0 → 1.0.0
  ├─ execa ^1.0.0 → 1.0.0
  ├─ is-fullwidth-code-point ^2.0.0 → 2.0.0
  ├─ is-fullwidth-code-point ^2.0.0
  ├─ lcid ^2.0.0 → 2.0.0
  ├─ locate-path ^3.0.0 → 3.0.0
  ├─ mem ^4.0.0 → 4.3.0
  ├─ string-width ^2.1.1 → 2.1.1
  ├─ strip-ansi ^4.0.0 → 4.0.0
├─ wrap-ansi ^2.0.0 → 2.1.0
  ├─ ansi-regex ^3.0.0 → 3.0.1
  ├─ color-convert ^1.9.0 → 1.9.3
  ├─ cross-spawn ^6.0.0 → 6.0.6
  ├─ get-stream ^4.0.0 → 4.1.0
  ├─ invert-kv ^2.0.0 → 2.0.0
  ├─ is-fullwidth-code-point ^2.0.0
  ├─ is-stream ^1.1.0 → 1.1.0
  ├─ map-age-cleaner ^0.1.1 → 0.1.3
  ├─ mimic-fn ^2.0.0 → 2.1.0
  ├─ npm-run-path ^2.0.0
  ├─ p-finally ^1.0.0
  ├─ p-is-promise ^2.0.0 → 2.1.0
  ├─ p-locate ^3.0.0 → 3.0.0
  ├─ path-exists ^3.0.0 → 3.0.0
  ├─ signal-exit ^3.0.0 → 3.0.7
  ├─ string-width ^1.0.1 → 1.0.2
  ├─ strip-ansi ^3.0.1 → 3.0.1
  ├─ strip-ansi ^4.0.0 → 4.0.0
├─ strip-eof ^1.0.0 → 1.0.0
  ├─ ansi-regex ^2.0.0 → 2.1.1
  ├─ ansi-regex ^3.0.0 → 3.0.1
  ├─ code-point-at ^1.0.0 → 1.1.0
  ├─ color-name 1.1.3 → 1.1.3
  ├─ is-fullwidth-code-point ^1.0.0 → 1.0.0
  ├─ nice-try ^1.0.4 → 1.0.5
  ├─ p-defer ^1.0.0
  ├─ p-limit ^2.0.0 → 2.2.2
  ├─ path-key ^2.0.1 → 2.0.1
  ├─ pump ^3.0.0 → 3.0.4
  ├─ semver ^5.5.0 → 5.7.2
  ├─ shebang-command ^1.2.0
  ├─ strip-ansi ^3.0.0 → 3.0.1
├─ which ^1.2.9 → 1.3.0
  ├─ ansi-regex ^2.0.0 → 2.1.1
  ├─ end-of-stream ^1.1.0 → 1.4.5
  ├─ isexe ^2.0.0 → 2.0.0
  ├─ number-is-nan ^1.0.0 → 1.0.1
  ├─ once ^1.3.1 → 1.4.0
├─ p-try ^2.0.0 → 2.2.0
  ├─ once ^1.4.0 → 1.4.0
├─ wrappy 1 → 1.0.2
  ├─ wrappy 1 → 1.0.2

SAST Findings (2)

CRITICAL GHSA-v8v8-6859-qxm4: Arbitrary shell command execution in logkitty osv

CVSS 9.8 (CRITICAL) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

Review Summary

Risk score: 43. Findings: 1 critical (+40), 1 low (+3).

Published to npm: