Skip to content
Tools / cloudflared / Dependencies

Dependency Analysis

cloudflared

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

95% Freshness
101 Dependencies
5 Outdated
0 Stale
16.6 Avg Behind

Dependency List

Latest release 2026.3.0

Dependency Type Current Latest Behind CVE License
google.golang.org/grpc
golang
Transitive v1.72.2 1 critical Apache-2.0
github.com/go-jose/go-jose/v4
golang
Direct v4.1.3 1 high Apache-2.0
go.opentelemetry.io/otel
golang
Direct v1.40.0 1 high Apache-2.0 AND BSD-3-Clause
go.opentelemetry.io/otel/sdk
golang
Direct v1.40.0 1 high Apache-2.0 AND BSD-3-Clause
pytest
pypi
Direct 7.3.1 9.0.3 30 behind 1 medium MIT
requests
pypi
Direct 2.28.2 2.34.2 15 behind 4 medium Apache-2.0
golang.org/x/crypto
golang
Direct v0.38.0 3 medium BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
github.com/go-chi/chi/v5
golang
Direct v5.2.2 1 unknown MIT
golang.org/x/net
golang
Direct v0.40.0 3 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang

License Breakdown

MIT 32
Apache-2.0 27
BSD-3-Clause 11
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 10
Apache-2.0 AND BSD-3-Clause 5
BSD-2-Clause 4
BSD-3-Clause AND LicenseRef-scancode-facebook-patent-rights-2 4
Unknown 4
Apache-2.0 AND BSD-3-Clause AND MIT 1
ISC 1
MIT OR (GPL-1.0-or-later AND MIT) 1

CVE Severity

critical 1
high 3
medium 3
low 0
unknown 2

Beta — feedback welcome: [email protected]