Skip to content
Tools / ArgoCD / Dependencies

Dependency Analysis

ArgoCD

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

60% Freshness
1708 Dependencies
586 Outdated
0 Stale
23.8 Avg Behind

Dependency List

Latest release v3.4.1

Dependency Type Current Latest Behind CVE License
fast-xml-parser
npm
Transitive 4.5.3 5.8.0 45 behind 6 critical MIT
minimatch
npm
Transitive 5.1.6 10.2.5 71 behind 1 high ISC
tar
npm
Transitive 6.2.1 7.5.16 27 behind 6 high ISC
@babel/plugin-transform-modules-systemjs
npm
Transitive 7.27.1 7.29.7 15 behind 1 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
serialize-javascript
npm
Transitive 5.0.1 7.0.5 9 behind 2 high BSD-3-Clause
immutable
npm
Transitive 5.1.3 5.1.6 5 behind 1 high MIT
path-to-regexp
npm
Transitive 0.1.12 8.4.2 5 behind 1 high MIT
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 2 high ISC
fast-uri
npm
Transitive 3.0.6 3.1.2 3 behind 2 high BSD-3-Clause
node-forge
npm
Transitive 1.3.1 1.4.0 3 behind 7 high BSD-3-Clause OR GPL-2.0 OR (BSD-3-Clause AND GPL-2.0)
github.com/moby/spdystream
golang
Transitive v0.5.0 1 high Apache-2.0
go.opentelemetry.io/otel
golang
Transitive v1.38.0 1 high Apache-2.0 AND BSD-3-Clause
minimatch
npm
Transitive 5.1.7 2 high ISC
esbuild
npm
Transitive 0.18.20 0.28.0 50 behind 1 medium MIT
ajv
npm
Direct 7.2.4 8.20.0 35 behind 1 medium MIT
qs
npm
Transitive 6.13.0 6.15.2 35 behind 2 medium BSD-3-Clause
postcss
npm
Transitive 8.4.49 8.5.15 16 behind 1 medium MIT
dompurify
npm
Transitive 3.2.6 3.4.8 15 behind 9 medium Apache-2.0 OR MPL-2.0
brace-expansion
npm
Transitive 2.0.2 5.0.6 11 behind 1 medium MIT
webpack-dev-server
npm
Direct 4.15.2 5.2.4 6 behind 2 medium MIT
js-yaml
npm
Transitive 3.14.1 4.2.0 5 behind 1 medium MIT
follow-redirects
npm
Transitive 1.15.9 1.16.0 3 behind 1 medium MIT
github.com/go-git/go-git/v5
golang
Direct v5.14.0 4 medium Apache-2.0
diff
npm
Transitive 4.0.2 9.0.0 18 behind 1 low BSD-3-Clause
@eslint/plugin-kit
npm
Transitive 0.3.3 0.7.2 11 behind 1 low Apache-2.0
@tootallnate/once
npm
Transitive 2.0.0 3.0.1 2 behind 1 low MIT
pygments
pypi
Direct 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause
golang.org/x/net
golang
Transitive v0.44.0 3 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
k8s.io/kubernetes
golang
Direct v1.34.2 2 unknown Apache-2.0
k8s.io/kubernetes
golang
Direct v1.34.2 2 unknown Apache-2.0

License Breakdown

MIT 1200
Apache-2.0 157
BSD-3-Clause 84
Unknown 76
ISC 66
BSD-2-Clause 39
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 18
Apache-2.0 AND BSD-3-Clause 8
Apache-2.0 AND MIT 7
LicenseRef-scancode-generic-cla AND MIT 6
MPL-2.0 5
Apache-2.0 AND BSD-3-Clause AND MIT 4
CC0-1.0 AND MIT 4
0BSD 3
BSD-2-Clause AND BSD-3-Clause 3
Unlicense 3
Apache-2.0 AND CC-BY-SA-4.0 2
CC-BY-4.0 2
ISC AND MIT 2
LicenseRef-scancode-public-domain AND Unlicense 2
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 1
Apache-2.0 OR MPL-1.1 OR (Apache-2.0 AND MPL-1.1) 1
Apache-2.0 OR MPL-2.0 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-2-Clause AND ISC 1
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND MIT 1
BSD-3-Clause AND MIT 1
BSD-3-Clause AND MPL-2.0 1
BSD-3-Clause OR GPL-2.0 OR (BSD-3-Clause AND GPL-2.0) 1
BlueOak-1.0.0 1
CC-BY-4.0 AND MIT AND OFL-1.1 1
GPL-3.0-only 1
MPL-1.0 AND MPL-2.0 1
Python-2.0 1

CVE Severity

critical 1
high 13
medium 10
low 4
unknown 3

Beta — feedback welcome: [email protected]