Skip to content
Tools / Docker Compose / Dependencies

Dependency Analysis

Docker Compose

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

98% Freshness
229 Dependencies
5 Outdated
0 Stale
8.6 Avg Behind

Dependency List

Latest release v5.1.3

Dependency Type Current Latest Behind CVE License
gitpython
pypi
Direct 3.1.11 8 critical BSD-2-Clause AND BSD-3-Clause
certifi
pypi
Direct 2021.5.30 3 high MPL-2.0
cryptography
pypi
Direct 3.3.2 10 high Apache-2.0 AND BSD-3-Clause AND PSF-2.0 AND Python-2.0
github.com/docker/docker
golang
Transitive v28.5.2+incompatible 2 high Apache-2.0
go.opentelemetry.io/otel/sdk
golang
Direct v1.42.0 1 high Apache-2.0 AND BSD-3-Clause
pyinstaller
pypi
Direct 4.1 2 high GPL-3.0-or-later
urllib3
pypi
Direct 1.26.5 7 high MIT
virtualenv
pypi
Direct 20.4.0 2 high MIT
filelock
pypi
Direct 3.0.12 2 medium Unlicense
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp
golang
Transitive v1.42.0 1 medium Unknown
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
golang
Transitive v1.42.0 1 medium Apache-2.0 AND BSD-3-Clause
idna
pypi
Direct 2.10 1 medium BSD-2-Clause
paramiko
pypi
Direct 2.7.2 2 medium LGPL-2.1-or-later
pynacl
pypi
Direct 1.4.0 1 medium Apache-2.0
requests
pypi
Direct 2.25.1 1 medium Apache-2.0
golang.org/x/net
golang
Transitive v0.51.0 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
py
pypi
Direct 1.10.0 1 unknown MIT

License Breakdown

MIT 62
Apache-2.0 51
Unknown 45
BSD-3-Clause 18
Apache-2.0 AND BSD-3-Clause 13
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 8
BSD-2-Clause 7
MPL-2.0 5
BSD-2-Clause AND BSD-3-Clause 4
LGPL-2.1-or-later 3
Apache-2.0 AND MIT 2
PSF-2.0 2
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-3-Clause AND MIT 1
Apache-2.0 AND BSD-3-Clause AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND CC-BY-SA-4.0 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 1
GPL-3.0-or-later 1
Python-2.0.1 1
Unlicense 1

CVE Severity

critical 1
high 7
medium 7
low 0
unknown 2

Beta — feedback welcome: [email protected]