Skip to content
Tools / gravity / Dependencies

Dependency Analysis

gravity

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

78% Freshness
951 Dependencies
168 Outdated
0 Stale
9.7 Avg Behind

Dependency List

Latest release v0.32.1

Dependency Type Current Latest Behind CVE License
yaml
npm
Transitive 2.2.2 2.9.0 27 behind 1 medium ISC
micromatch
npm
Transitive 4.0.5 4.0.8 3 behind 1 medium MIT
golang.org/x/net
golang
Direct 0.39.0 3 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang

License Breakdown

MIT 546
Apache-2.0 167
Unknown 86
BSD-3-Clause 40
ISC 40
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 16
BSD-2-Clause 12
MPL-2.0 10
Apache-2.0 AND BSD-3-Clause 9
Apache-2.0 AND MIT 4
Apache-2.0 AND BSD-3-Clause AND MIT 2
CC0-1.0 AND MIT 2
Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause 1
Apache-2.0 AND CC-BY-SA-4.0 1
Apache-2.0 AND GPL-1.0-or-later AND GPL-3.0-only 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 1
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-3-Clause AND MIT 1
CC-BY-4.0 1
GPL-3.0 AND GPL-3.0-only 1
ISC AND MIT 1
JSON AND MIT 1
LicenseRef-scancode-dco-1.1 AND MIT 1
MIT OR (MIT AND WTFPL) 1
MPL-1.0 AND MPL-2.0 1
Python-2.0 1

CVE Severity

critical 0
high 0
medium 2
low 0
unknown 1

Beta — feedback welcome: [email protected]