Skip to content
Tools / grist-core / Dependencies

Dependency Analysis

grist-core

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

55% Freshness
1617 Dependencies
591 Outdated
0 Stale
7.5 Avg Behind

Dependency List

Latest release v1.7.13

Dependency Type Current Latest Behind CVE License
chardet
pypi
Direct 5.1.0 7.4.3 14 behind LGPL-2.1-or-later
astroid
pypi
Direct 2.14.2 GPL-3.0-or-later AND LGPL-2.1-or-later
jszip
npm
Transitive 3.10.1 3.10.1 Current GPL-3.0-only OR MIT
node-forge
npm
Transitive 1.4.0 1.4.0 Current BSD-3-Clause OR GPL-2.0-only

License Breakdown

MIT 1278
ISC 112
Apache-2.0 74
BSD-2-Clause 37
BSD-3-Clause 31
Unknown 24
BlueOak-1.0.0 10
CC0-1.0 AND MIT 7
Apache-2.0 AND MIT 5
0BSD 3
CC0-1.0 3
ISC AND MIT 2
LicenseRef-scancode-unknown-license-reference AND MIT 2
Unlicense 2
(MPL-2.0 OR Apache-2.0) 1
Apache-2.0 AND Apache-2.0 WITH LLVM-exception 1
Apache-2.0 AND Unlicense 1
Apache-2.0 OR Unlicense OR (Apache-2.0 AND Unlicense) 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-3-Clause AND LicenseRef-scancode-generic-cla AND MIT 1
BSD-3-Clause AND MIT 1
BSD-3-Clause OR GPL-2.0-only 1
CC-BY-4.0 1
CC-BY-SA-4.0 AND ISC 1
GPL-3.0-only OR MIT 1
GPL-3.0-or-later AND LGPL-2.1-or-later 1
LGPL-2.1-or-later 1
LicenseRef-scancode-json-pd 1
LicenseRef-scancode-public-domain 1
LicenseRef-scancode-public-domain AND Unlicense 1
MIT AND MIT-0 1
MIT AND Ruby 1
MIT AND Unlicense 1
MIT AND Zlib 1
MIT OR WTFPL OR (MIT AND WTFPL) 1
MIT-0 1
MPL-2.0 1
Python-2.0 1
Python-2.0.1 1
WTFPL 1

CVE Severity

critical 0
high 12
medium 8
low 3
unknown 0

Beta — feedback welcome: [email protected]