Skip to content
Tools / groceries / Dependencies

Dependency Analysis

groceries

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

44% Freshness
1371 Dependencies
643 Outdated
0 Stale
23.7 Avg Behind

Dependency List

Latest release v1.1.9

Dependency Type Current Latest Behind CVE License
node-forge
npm
Transitive 1.3.1 1.4.0 3 behind 7 high BSD-3-Clause OR GPL-2.0 OR (BSD-3-Clause AND GPL-2.0)
jszip
npm
Direct 3.10.1 3.10.1 Current GPL-3.0-only OR MIT

License Breakdown

MIT 1059
ISC 124
Apache-2.0 86
BSD-2-Clause 23
BSD-3-Clause 17
Unknown 13
BlueOak-1.0.0 7
Apache-2.0 AND MIT 6
CC0-1.0 AND MIT 4
MIT OR (CC0-1.0 AND MIT) 4
ISC AND MIT 3
Unlicense 3
0BSD 2
BSD-2-Clause AND BSD-2-Clause-Views 2
Python-2.0 2
0BSD AND ISC AND MIT 1
Apache-2.0 AND BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 1
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-3-Clause OR GPL-2.0 OR (BSD-3-Clause AND GPL-2.0) 1
CC-BY-3.0 1
CC-BY-4.0 1
CC-BY-SA-4.0 AND ISC 1
CC0-1.0 1
GPL-3.0-only OR MIT 1
LicenseRef-scancode-public-domain AND Unlicense 1
MIT AND MIT-0 1
MIT AND Zlib 1
MIT OR (MIT AND WTFPL) 1
WTFPL OR (MIT AND WTFPL) 1

CVE Severity

critical 3
high 29
medium 14
low 8
unknown 0

Beta — feedback welcome: [email protected]