Skip to content
Tools / commafeed / Dependencies

Dependency Analysis

commafeed

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

73% Freshness
561 Dependencies
117 Outdated
0 Stale
17.3 Avg Behind

Dependency List

Latest release 7.1.0

Dependency Type Current Latest Behind CVE License
dompurify
npm
Transitive 3.2.7 3.4.8 14 behind 8 medium Apache-2.0 OR MPL-2.0

License Breakdown

MIT 424
Unknown 59
Apache-2.0 19
ISC 12
MPL-2.0 12
MIT OR Apache-2.0 9
BSD-3-Clause 7
BSD-2-Clause 2
MIT-0 2
(MIT OR CC0-1.0) 1
0BSD 1
Apache-2.0 AND Apache-2.0 WITH LLVM-exception 1
Apache-2.0 AND BSD-3-Clause AND MIT 1
Apache-2.0 AND OFL-1.1 AND Ubuntu-font-1.0 1
Apache-2.0 AND WTFPL 1
Apache-2.0 OR MPL-2.0 1
BSD-3-Clause AND ISC AND MIT 1
BSD-3-Clause AND LicenseRef-scancode-generic-cla AND MIT 1
BlueOak-1.0.0 1
CC-BY-4.0 1
CC0-1.0 1
LicenseRef-scancode-unicode AND LicenseRef-scancode-unknown-license-reference AND Unicode-3.0 1
MIT AND BSD-3-Clause 1

CVE Severity

critical 0
high 0
medium 1
low 0
unknown 0

Beta — feedback welcome: [email protected]