Skip to content
Tools / fider / Dependencies

Dependency Analysis

fider

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

54% Freshness
1523 Dependencies
578 Outdated
0 Stale
18.6 Avg Behind

Dependency List

Latest release v0.35.0

Dependency Type Current Latest Behind CVE License
protobufjs
npm
Transitive 7.5.4 8.6.0 22 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
playwright
npm
Transitive 1.48.2 1.60.0 889 behind 1 high Apache-2.0
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
@babel/plugin-transform-modules-systemjs
npm
Transitive 7.25.9 7.29.7 21 behind 1 high MIT
semver
npm
Transitive 7.3.7 7.8.2 21 behind 1 high ISC
svgo
npm
Transitive 2.8.0 4.0.1 19 behind 1 high MIT
immutable
npm
Transitive 4.3.7 5.1.6 15 behind 1 high MIT
fast-uri
npm
Transitive 3.0.3 3.1.2 6 behind 2 high BSD-3-Clause
braces
npm
Transitive 2.3.2 3.0.3 4 behind 1 high MIT
jws
npm
Transitive 4.0.0 4.0.1 2 behind 1 high MIT
github.com/gomarkdown/markdown
golang
Direct v0.0.0-20250207164621-7a1f277a159e 1 high BSD-2-Clause
glob
npm
Transitive 11.0.0 1 high CC-BY-SA-4.0 AND ISC
postcss
npm
Transitive 5.2.18 8.5.15 170 behind 2 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
yaml
npm
Transitive 1.10.2 2.9.0 49 behind 1 medium ISC
esbuild
npm
Transitive 0.21.5 0.28.0 28 behind 1 medium MIT
nanoid
npm
Transitive 3.3.7 5.1.11 24 behind 1 medium MIT
postcss
npm
Transitive 8.4.47 8.5.15 18 behind 1 medium MIT
brace-expansion
npm
Transitive 2.0.2 5.0.6 11 behind 1 medium MIT
dompurify
npm
Direct 3.3.2 3.4.8 10 behind 4 medium (Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0)
markdown-it
npm
Transitive 14.1.0 14.2.0 2 behind 1 medium MIT
micromatch
npm
Transitive 3.1.0 1 medium MIT
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 1 low MIT
diff
npm
Transitive 4.0.2 9.0.0 18 behind 1 low BSD-3-Clause
tmp
npm
Transitive 0.2.3 0.2.7 4 behind 1 low MIT
@tootallnate/once
npm
Transitive 2.0.0 3.0.1 2 behind 1 low MIT
github.com/disintegration/imaging
golang
Transitive v1.6.2 1 low MIT
github.com/aws/aws-sdk-go
golang
Direct v1.41.14 2 unknown Apache-2.0
golang.org/x/image
golang
Transitive v0.38.0 2 unknown Unknown
golang.org/x/net
golang
Direct v0.50.0 2 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang

License Breakdown

MIT 1208
Apache-2.0 69
ISC 66
BSD-3-Clause 62
BSD-2-Clause 35
Unknown 14
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 9
Apache-2.0 AND MIT 6
CC0-1.0 AND MIT 6
GPL-3.0 AND GPL-3.0-only 6
MPL-2.0 6
BlueOak-1.0.0 5
BSD-3-Clause AND MIT 3
0BSD 2
Apache-2.0 AND BSD-2-Clause 2
BSD-3-Clause AND CC-BY-3.0 2
ISC AND MIT 2
LicenseRef-scancode-public-domain AND Unlicense 2
(Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0) 1
Apache-2.0 AND BSD-3-Clause 1
Apache-2.0 OR MIT 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
CC-BY-4.0 1
CC-BY-SA-4.0 AND ISC 1
CC0-1.0 1
FTL OR GPL-2.0-or-later 1
GPL-1.0-or-later AND GPL-3.0 AND GPL-3.0-only 1
LicenseRef-scancode-unknown-license-reference AND MIT 1
MIT OR (MIT AND Unlicense) 1
MIT OR WTFPL OR (MIT AND WTFPL) 1
MPL-1.0 AND MPL-2.0 1
OFL-1.1 1
Python-2.0 1

CVE Severity

critical 1
high 11
medium 10
low 5
unknown 3

Beta — feedback welcome: [email protected]