Skip to content
Tools / esphome / Dependencies

Dependency Analysis

esphome

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

99% Freshness
87 Dependencies
0 Outdated
0 Stale
0.0 Avg Behind

Dependency List

Latest release 2026.4.4

Dependency Type Current Latest Behind CVE License
pytest-asyncio
pypi
Direct 1.3.0 1.4.0 4 behind Apache-2.0
pytest-asyncio
pypi
Direct 1.3.0 1.4.0 4 behind Apache-2.0
requests
pypi
Direct 2.33.1 2.34.2 4 behind Apache-2.0
ruff
pypi
Direct 0.15.12 0.15.15 3 behind MIT
ruff
pypi
Direct 0.15.12 0.15.15 3 behind MIT
click
pypi
Direct 8.3.3 8.4.1 2 behind BSD-3-Clause
tornado
pypi
Direct 6.5.5 6.5.6 1 behind Apache-2.0

License Breakdown

Unknown 39
MIT 21
Apache-2.0 8
BSD-2-Clause 3
BSD-2-Clause AND BSD-3-Clause 3
BSD-3-Clause 3
GPL-1.0-or-later AND GPL-3.0 AND GPL-3.0-only 2
GPL-2.0-only AND CC-BY-4.0 AND CC-BY-SA-4.0 2
MPL-2.0 2
GPL-3.0-or-later AND LGPL-3.0 AND LGPL-3.0-only 1
LGPL-2.1-only 1
MIT-CMU 1

CVE Severity

critical 0
high 1
medium 0
low 0
unknown 0

Beta — feedback welcome: [email protected]