Skip to content
Tools / figranium / Dependencies

Dependency Analysis

figranium

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

52% Freshness
1914 Dependencies
744 Outdated
0 Stale
10.1 Avg Behind

Dependency List

Latest release v0.12.2

Dependency Type Current Latest Behind CVE License
@opentelemetry/api
npm
Transitive 1.9.0 1.9.1 1 behind Apache-2.0 OR (Apache-2.0 AND LGPL-3.0-only)
@opentelemetry/api
npm
Transitive 1.9.0 1.9.1 1 behind Apache-2.0 OR (Apache-2.0 AND LGPL-3.0-only)
jszip
npm
Direct 3.10.1 3.10.1 Current GPL-3.0-only OR MIT
jszip
npm
Direct 3.10.1 3.10.1 Current GPL-3.0-only OR MIT

License Breakdown

MIT 1488
Apache-2.0 158
ISC 95
BSD-3-Clause 44
BlueOak-1.0.0 26
MPL-2.0 24
BSD-2-Clause 22
Unknown 11
Apache-2.0 AND MIT 4
CC0-1.0 AND MIT 4
0BSD AND ISC AND MIT 2
Apache-2.0 OR (Apache-2.0 AND LGPL-3.0-only) 2
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 2
BSD-2-Clause AND BSD-3-Clause 2
BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 2
BSD-2-Clause AND JSON 2
BSD-3-Clause AND LicenseRef-scancode-generic-cla AND MIT 2
BSD-3-Clause AND LicenseRef-scancode-protobuf 2
CC-BY-3.0 2
CC-BY-4.0 2
CC0-1.0 2
CC0-1.0 OR MIT OR (CC0-1.0 AND MIT) 2
GPL-3.0-only OR MIT 2
ISC AND MIT 2
MIT AND Zlib 2
MIT OR (CC0-1.0 AND MIT) 2
MIT OR (MIT AND WTFPL) 2
Python-2.0 2
0BSD 1

CVE Severity

critical 4
high 15
medium 7
low 2
unknown 0

Beta — feedback welcome: [email protected]