Skip to content
Tools / Guardrails / Dependencies

Dependency Analysis

Guardrails

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

58% Freshness
333 Dependencies
90 Outdated
0 Stale
2.6 Avg Behind

Dependency List

Latest release v0.21.0

Dependency Type Current Latest Behind CVE License
langchain-core
pypi
Direct 1.2.17 1.4.0 27 behind 2 high Unknown
gitpython
pypi
Transitive 3.1.46 3.1.50 4 behind 4 high BSD-3-Clause
pillow
pypi
Transitive 11.3.0 12.2.0 4 behind 6 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
simpleeval
pypi
Direct 1.0.3 1.0.7 4 behind 1 high LicenseRef-scancode-warranty-disclaimer AND MIT
tornado
pypi
Direct 6.5.4 6.5.6 2 behind 3 high Apache-2.0
pyasn1
pypi
Transitive 0.6.2 0.6.3 1 behind 1 high BSD-2-Clause AND BSD-3-Clause AND MIT
langsmith
pypi
Transitive 0.7.12 0.8.9 36 behind 1 medium Unknown
scikit-learn
pypi
Direct 1.2.2 1.9.0 23 behind 1 medium BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference
requests
pypi
Transitive 2.32.5 2.34.2 6 behind 1 medium Apache-2.0
cryptography
pypi
Transitive 46.0.5 48.0.0 4 behind 2 medium Apache-2.0 AND BSD-3-Clause
pytest
pypi
Direct 8.4.2 9.0.3 4 behind 1 medium MIT
aiohttp
pypi
Direct 3.13.3 3.14.0 3 behind 10 medium Apache-2.0 AND MIT
langchain-text-splitters
pypi
Transitive 1.1.1 1.1.2 1 behind 1 medium Unknown
langchain-openai
pypi
Direct 1.1.10 1.2.2 9 behind 1 low MIT
pygments
pypi
Transitive 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause

License Breakdown

Unknown 105
MIT 100
Apache-2.0 42
BSD-3-Clause 20
BSD-2-Clause AND BSD-3-Clause 15
BSD-2-Clause 10
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 2
Apache-2.0 AND MIT 2
BSD-2-Clause AND BSD-3-Clause AND MIT 2
BSD-3-Clause AND MIT 2
MIT AND MPL-2.0 2
MPL-2.0 2
(Apache-2.0 AND BSD-3-Clause AND MIT) OR (Apache-2.0 AND MIT) 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-3-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 1
Apache-2.0 AND CC-BY-NC-4.0 AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND MIT AND MPL-2.0 1
Apache-2.0 AND Python-2.0 1
BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND MIT 1
CC-BY-4.0 AND LicenseRef-scancode-public-domain AND MIT 1
CNRI-Python AND Apache-2.0 1
ISC 1
LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
LicenseRef-scancode-warranty-disclaimer AND MIT 1
MIT AND HPND-Markus-Kuhn 1
MIT AND PSF-2.0 1
MIT AND Python-2.0 1
MIT AND ZPL-2.1 1
MIT-0 1
PSF-2.0 1
PSF-2.0 AND Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Python-2.0 AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1

CVE Severity

critical 0
high 6
medium 7
low 2
unknown 0

Beta — feedback welcome: [email protected]