Skip to content
Tools / ART / Dependencies

Dependency Analysis

ART

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

47% Freshness
1413 Dependencies
590 Outdated
0 Stale
11.3 Avg Behind

Dependency List

Latest release v0.5.17

Dependency Type Current Latest Behind CVE License
litellm
pypi
Direct 1.82.0 1.88.0.dev1 44 behind 6 critical LicenseRef-scancode-commercial-license AND LicenseRef-scancode-other-permissive AND MIT
vllm
pypi
Direct 0.13.0 0.22.0 16 behind 3 critical Apache-2.0
mlflow
pypi
Transitive 3.10.1 3.13.0 9 behind 3 critical Unknown
basic-ftp
npm
Transitive 5.0.5 6.0.1 8 behind 4 critical Apache-2.0 AND MIT
form-data
npm
Transitive 4.0.2 4.0.5 6 behind 1 critical MIT
nltk
pypi
Direct 3.9.1 3.9.4 3 behind 7 critical Apache-2.0
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
axios
npm
Transitive 1.8.4 1.17.0 27 behind 17 high MIT
tar
npm
Transitive 6.2.1 7.5.16 27 behind 6 high ISC
langchain-core
pypi
Direct 1.2.21 1.4.0 23 behind 2 high Unknown
mcp
pypi
Direct 1.13.0 1.27.2 23 behind 1 high MIT AND Python-2.0
cryptography
pypi
Transitive 43.0.3 48.0.0 22 behind 3 high BSD-3-Clause OR Apache-2.0
protobuf
pypi
Direct 6.32.0 7.35.0 19 behind 1 high BSD-3-Clause AND LicenseRef-scancode-protobuf
python-multipart
pypi
Direct 0.0.20 0.0.30 10 behind 1 high Apache-2.0
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
tar-fs
npm
Transitive 3.0.8 3.1.2 9 behind 2 high MIT
pyopenssl
pypi
Direct 24.2.1 26.2.0 8 behind 2 high Apache-2.0
python-multipart
pypi
Transitive 0.0.22 0.0.30 8 behind 2 high Apache-2.0
aiohttp
pypi
Direct 3.12.15 3.14.0 7 behind 8 high Apache-2.0 AND MIT
cbor2
pypi
Direct 5.8.0 6.1.2 7 behind 1 high MIT
fickling
pypi
Direct 0.1.4 0.1.11 7 behind 14 high GPL-3.0-only AND LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later
xgrammar
pypi
Transitive 0.1.29 0.2.1 7 behind 1 high Apache-2.0
lxml
pypi
Direct 6.0.0 6.1.1 6 behind 1 high BSD-3-Clause AND GPL-1.0-or-later
onnx
pypi
Transitive 1.20.1 1.21.0 5 behind 6 high Unknown
path-to-regexp
npm
Transitive 0.1.12 8.4.2 5 behind 1 high MIT
urllib3
pypi
Direct 2.5.0 2.7.0 5 behind 3 high MIT
wheel
pypi
Transitive 0.45.1 0.47.0 5 behind 1 high MIT
gitpython
pypi
Transitive 3.1.46 3.1.50 4 behind 4 high BSD-3-Clause
pillow
pypi
Direct 11.3.0 12.2.0 4 behind 1 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
tornado
pypi
Direct 6.5.2 6.5.6 4 behind 3 high Apache-2.0
fast-uri
npm
Transitive 3.0.6 3.1.2 3 behind 2 high BSD-3-Clause
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
ray
pypi
Transitive 2.54.0 2.55.1 3 behind 1 high Unknown
socket.io-parser
npm
Transitive 4.2.4 4.2.6 3 behind 1 high MIT
diffusers
pypi
Transitive 0.37.0 0.38.0 2 behind 1 high Unknown
mako
pypi
Transitive 1.3.10 1.3.12 2 behind 2 high MIT
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
pillow
pypi
Direct 12.1.1 12.2.0 1 behind 5 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
pdfminer-six
pypi
Direct 20240706 20260107.0.0 2 high Unknown
vllm
pypi
Direct 0.17.0+art1 0.22.0 6 high Unknown
awscli
pypi
Direct 1.44.27 1.45.22 83 behind 1 medium Unknown
qs
npm
Transitive 6.13.0 6.15.2 35 behind 2 medium BSD-3-Clause
langsmith
pypi
Transitive 0.7.22 0.8.9 26 behind 1 medium Unknown
transformers
pypi
Direct 4.57.3 5.10.1 26 behind 1 medium Apache-2.0
anthropic
pypi
Transitive 0.86.0 0.105.2 24 behind 2 medium Unknown
filelock
pypi
Direct 3.19.1 3.29.1 20 behind 2 medium Unlicense
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
cryptography
pypi
Direct 45.0.6 48.0.0 11 behind 1 medium Apache-2.0 OR BSD-3-Clause OR (Apache-2.0 AND BSD-3-Clause)
fonttools
pypi
Direct 4.59.1 4.63.0 9 behind 1 medium Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1
yaml
npm
Transitive 2.7.1 2.9.0 9 behind 1 medium ISC
ip-address
npm
Transitive 9.0.5 10.2.0 6 behind 1 medium MIT
requests
pypi
Transitive 2.32.5 2.34.2 6 behind 1 medium Apache-2.0
js-yaml
npm
Transitive 3.14.1 4.2.0 5 behind 1 medium MIT
ajv
npm
Transitive 8.17.1 8.20.0 4 behind 1 medium MIT
ray
pypi
Direct 2.53.0 2.55.1 4 behind 1 medium Unknown
aiohttp
pypi
Transitive 3.13.3 3.14.0 3 behind 10 medium Apache-2.0 AND MIT
follow-redirects
npm
Transitive 1.15.9 1.16.0 3 behind 1 medium MIT
lxml-html-clean
pypi
Direct 0.4.2 0.4.5 3 behind 2 medium BSD-3-Clause
pip
pypi
Transitive 26.0.1 26.1.2 3 behind 2 medium MIT
python-dotenv
pypi
Direct 1.1.1 1.2.2 3 behind 1 medium BSD-3-Clause
mdast-util-to-hast
npm
Transitive 13.2.0 13.2.1 1 behind 1 medium MIT
pytest
pypi
Direct 9.0.2 9.0.3 1 behind 1 medium MIT
diskcache
pypi
Transitive 5.6.3 5.6.3 Current 1 medium Apache-2.0
langchain-openai
pypi
Direct 1.1.10 1.2.2 9 behind 1 low MIT
tmp
npm
Transitive 0.0.33 0.2.7 9 behind 1 low MIT
pygments
pypi
Transitive 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause

License Breakdown

MIT 771
Unknown 177
Apache-2.0 140
BSD-3-Clause 85
BSD-2-Clause AND BSD-3-Clause 40
ISC 35
BSD-2-Clause 21
Elastic-2.0 8
LGPL-3.0-or-later 8
Apache-2.0 AND MIT 7
MPL-2.0 6
MIT AND Python-2.0 5
Apache-2.0 AND BSD-2-Clause 4
CC0-1.0 AND MIT 4
LicenseRef-scancode-generic-cla AND MIT 4
Unlicense 4
0BSD 3
Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1 3
Apache-2.0 OR BSD-3-Clause OR (Apache-2.0 AND BSD-3-Clause) 3
BSD-3-Clause AND LicenseRef-scancode-protobuf 3
BSD-3-Clause AND MIT 3
CNRI-Python AND Apache-2.0 3
LicenseRef-scancode-commercial-license AND LicenseRef-scancode-other-permissive AND MIT 3
PSF-2.0 3
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 2
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 2
Apache-2.0 AND LGPL-3.0-or-later 2
BSD-2-Clause AND BSD-3-Clause AND MIT 2
BSD-3-Clause AND CC0-1.0 AND ISC AND MIT 2
BSD-3-Clause AND ISC 2
CAL-1.0 AND LicenseRef-scancode-unknown AND PSF-2.0 AND Python-2.0 2
LGPL-2.1-only 2
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 2
MIT AND MPL-2.0 2
MIT AND ZPL-2.1 2
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 2
(Apache-2.0 AND BSD-3-Clause AND MIT) OR (Apache-2.0 AND MIT) 1
0BSD AND BSD-2-Clause AND BSD-3-Clause AND BSD-4-Clause AND LicenseRef-scancode-python-cwi AND LicenseRef-scancode-secret-labs-2011 AND LicenseRef-scancode-unicode AND MIT AND Python-2.0 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 1
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC0-1.0 AND LicenseRef-scancode-public-domain 1
Apache-2.0 AND LGPL-3.0-or-later AND MIT 1
Apache-2.0 AND LicenseRef-scancode-free-unknown 1
Apache-2.0 AND LicenseRef-scancode-generic-cla 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference AND BSD-3-Clause AND BSD-3-Clause AND MIT 1
Apache-2.0 AND MIT AND MPL-2.0 1
Apache-2.0 AND Python-2.0 1
BSD-2-Clause AND BSD-3-Clause AND BSD-3-Clause-Modification AND HPND AND LicenseRef-scancode-proprietary-license 1
BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later 1
BSD-2-Clause AND BSD-3-Clause AND ISC 1
BSD-2-Clause AND BSD-3-Clause AND ISC AND Python-2.0 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain AND Unlicense 1
BSD-3-Clause AND GPL-1.0-or-later 1
BSD-3-Clause AND GPL-1.0-or-later AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause AND MIT AND LicenseRef-scancode-bsd-plus-mod-notice AND HPND AND LicenseRef-scancode-other-permissive AND LicenseRef-scancode-warranty-disclaimer AND BSD-2-Clause AND BSD-3-Clause AND MIT AND MPL-2.0 AND MPL-2.0 AND MIT 1
BSD-3-Clause AND Python-2.0 1
BSD-3-Clause OR Apache-2.0 1
CC0-1.0 AND Unlicense 1
GPL-3.0-only AND LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 1
ISC AND MIT 1
ISC AND MPL-2.0 1
LGPL-2.0-only AND LGPL-2.1 AND LGPL-2.1-only 1
LGPL-2.0-or-later AND LGPL-2.1-only 1
LGPL-2.0-or-later AND LGPL-3.0-or-later 1
LGPL-2.1-or-later 1
LGPL-3.0-only 1
LicenseRef-scancode-apple-excl AND LicenseRef-scancode-unknown 1
LicenseRef-scancode-free-unknown AND MIT 1
LicenseRef-scancode-unknown-license-reference AND MIT AND Python-2.0 1
MIT AND HPND 1
MIT AND HPND-Markus-Kuhn 1
MIT AND PSF-2.0 1
MIT AND Python-2.0 AND MIT 1
MIT-0 1
MPL-2.0 AND Apache-2.0 1
PSF-2.0 AND Python-2.0 1
Python-2.0 1
ZPL-2.1 1

CVE Severity

critical 6
high 34
medium 23
low 3
unknown 0

Beta — feedback welcome: [email protected]