npm vulnerability intelligence

@tootallnate/once NPM Package
Vulnerability Check

Creates a Promise that waits for a single event

Low severity MIT v3.0.1
Vulnerability Analysis OSV Live

@tootallnate/once

v3.0.1 · MIT · 50,733,352 dl/wk

Advisory Breakdown

Critical 0
High 0
Moderate 0
Low 1

Severity Rating

Low severity

1 advisory

Low severity

Weekly downloads

50,733,352

Total advisories

1

Latest version

3.0.1

License

MIT

Known advisories

OSV records for the npm ecosystem

1
GHSA-vpq2-c234-7xj6 CVE-2026-3449 low

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

Affected: >=3.0.0 <3.0.1, >=0 <2.0.1 Fixed in: 3.0.1, 2.0.1 Updated May 21, 2026
View source

Checked Jun 12, 2026, 6:19 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
@tootallnate/once
Ecosystem
npm
Latest version
3.0.1
License
MIT
Weekly downloads
50,733,352

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 6/12/2026, 6:19:16 PM