Skip to content
Tools / Docker Compose / Dependencies

Dependency Analysis

Docker Compose

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

98% Freshness
229 Dependencies
5 Outdated
0 Stale
8.6 Avg Behind

Dependency List

Latest release v5.1.3

Dependency Type Current Latest Behind CVE License
pyparsing
pypi
Direct 2.4.7 3.3.2 40 behind MIT
docker
pypi
Direct 5.0.0 7.1.0 15 behind Apache-2.0
bcrypt
pypi
Direct 3.2.0 5.0.0 12 behind Apache-2.0
pyyaml
pypi
Direct 5.4.1 6.0.3 6 behind MIT
distro
pypi
Direct 1.5.0 1.9.0 4 behind Apache-2.0

License Breakdown

MIT 62
Apache-2.0 51
Unknown 45
BSD-3-Clause 18
Apache-2.0 AND BSD-3-Clause 13
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 8
BSD-2-Clause 7
MPL-2.0 5
BSD-2-Clause AND BSD-3-Clause 4
LGPL-2.1-or-later 3
Apache-2.0 AND MIT 2
PSF-2.0 2
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-3-Clause AND MIT 1
Apache-2.0 AND BSD-3-Clause AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND CC-BY-SA-4.0 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 1
GPL-3.0-or-later 1
Python-2.0.1 1
Unlicense 1

CVE Severity

critical 1
high 7
medium 7
low 0
unknown 2

Beta — feedback welcome: [email protected]