Skip to content
Tools / helicone / Dependencies

Dependency Analysis

helicone

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

42% Freshness
5688 Dependencies
2875 Outdated
0 Stale
33.8 Avg Behind

Dependency List

Latest release v2025.08.21-1

Dependency Type Current Latest Behind CVE License
next
npm
Direct 15.2.4 16.2.7 738 behind 2 critical MIT
better-auth
npm
Transitive 1.3.6 1.6.14 184 behind 4 critical MIT
fast-xml-parser
npm
Transitive 5.2.5 5.8.0 35 behind 7 critical MIT
fast-xml-parser
npm
Transitive 5.2.5 5.8.0 35 behind 7 critical MIT
protobufjs
npm
Transitive 7.5.3 8.5.0 21 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
protobufjs
npm
Transitive 7.5.3 8.5.0 21 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
convict
npm
Transitive 6.2.4 6.2.5 1 behind 2 critical Apache-2.0
handlebars
npm
Transitive 4.7.8 4.7.9 1 behind 8 critical MIT
handlebars
npm
Transitive 4.7.8 4.7.9 1 behind 8 critical MIT
handlebars
npm
Transitive 4.7.8 4.7.9 1 behind 8 critical MIT
next
npm
Direct 14.2.31 16.2.7 524 behind 8 high MIT
drizzle-orm
npm
Transitive 0.33.0 0.45.2 523 behind 1 high Apache-2.0
langchain
npm
Direct 0.3.30 1.4.4 120 behind 1 high MIT
@langchain/core
npm
Transitive 0.3.67 1.1.48 109 behind 1 high MIT
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
wrangler
npm
Transitive 4.35.0 4.97.0 90 behind 1 high MIT OR Apache-2.0
undici
npm
Transitive 5.29.0 8.3.0 45 behind 5 high MIT
vite
npm
Transitive 7.2.7 8.0.16 40 behind 3 high BSD-2-Clause AND CC0-1.0 AND ISC AND MIT
undici
npm
Transitive 7.16.0 8.3.0 33 behind 1 high MIT
tar
npm
Transitive 6.2.1 7.5.16 27 behind 6 high ISC
glob
npm
Transitive 10.3.10 13.0.6 26 behind 1 high CC-BY-SA-4.0 AND ISC
glob
npm
Transitive 10.3.10 13.0.6 26 behind 1 high CC-BY-SA-4.0 AND ISC
nodemailer
npm
Direct 6.10.1 8.0.10 24 behind 4 high MIT AND MIT-0
protobuf
pypi
Direct 4.25.8 7.35.0 24 behind 1 high BSD-3-Clause
axios
npm
Transitive 1.11.0 1.17.0 23 behind 1 high MIT
rollup
npm
Transitive 4.53.3 4.61.0 21 behind 1 high 0BSD AND ISC AND MIT
@modelcontextprotocol/sdk
npm
Direct 1.20.2 1.29.0 20 behind 3 high MIT
next-mdx-remote
npm
Transitive 4.4.1 6.0.0 19 behind 1 high MPL-2.0
fastify
npm
Direct 4.29.1 5.8.5 17 behind 3 high BSD-2-Clause AND BSD-3-Clause AND MIT
kysely
npm
Transitive 0.28.5 0.29.2 16 behind 2 high MIT
starlette
pypi
Direct 0.47.2 1.2.1 16 behind 1 high BSD-2-Clause AND BSD-3-Clause
thrift
npm
Transitive 0.11.0 0.23.0 16 behind 2 high Apache-2.0
axios
npm
Direct 1.13.2 1.17.0 15 behind 16 high MIT
preact
npm
Transitive 10.27.0 10.29.2 14 behind 1 high MIT
fast-uri
npm
Transitive 2.4.0 3.1.2 10 behind 2 high MIT
aiohttp
pypi
Direct 3.12.14 3.14.0 8 behind 18 high Apache-2.0
devalue
npm
Transitive 5.6.0 5.8.1 8 behind 6 high MIT
tar-fs
npm
Transitive 2.1.3 3.1.2 7 behind 1 high MIT
path-to-regexp
npm
Transitive 8.2.0 8.4.2 6 behind 2 high MIT
pillow
pypi
Direct 11.1.0 12.2.0 6 behind 5 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
path-to-regexp
npm
Transitive 0.1.12 8.4.2 5 behind 1 high MIT
urllib3
pypi
Direct 2.5.0 2.7.0 5 behind 3 high MIT
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 2 high ISC
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 2 high ISC
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 2 high ISC
lodash-es
npm
Transitive 4.17.21 4.18.1 4 behind 3 high CC0-1.0 AND MIT
defu
npm
Transitive 6.1.4 6.1.7 3 behind 1 high MIT
defu
npm
Transitive 6.1.4 6.1.7 3 behind 1 high MIT
jws
npm
Transitive 3.2.2 4.0.1 3 behind 1 high MIT
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
@hapi/content
npm
Transitive 6.0.0 6.0.2 2 behind 1 high BSD-3-Clause
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
@isaacs/brace-expansion
npm
Transitive 5.0.0 5.0.1 1 behind 1 high MIT
xlsx
npm
Direct 0.18.5 0.18.5 Current 2 high Apache-2.0
next
npm
Direct 14.2.30 16.2.7 601 behind 2 medium MIT
next
npm
Direct 14.2.30 16.2.7 601 behind 2 medium MIT
langsmith
npm
Transitive 0.3.54 0.7.4 115 behind 3 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
vite
npm
Transitive 7.1.5 8.0.16 65 behind 1 medium BSD-2-Clause AND CC0-1.0 AND ISC AND MIT
transformers
pypi
Direct 4.55.0 5.10.1 37 behind 1 medium Apache-2.0
qs
npm
Transitive 6.13.0 6.15.2 35 behind 2 medium BSD-3-Clause
postcss
npm
Transitive 8.4.31 8.5.15 34 behind 1 medium MIT
filelock
pypi
Direct 3.16.1 3.29.1 23 behind 2 medium Unlicense
dompurify
npm
Transitive 3.2.6 3.4.8 15 behind 9 medium Apache-2.0 OR MPL-2.0
brace-expansion
npm
Transitive 2.0.2 5.0.6 11 behind 1 medium MIT
brace-expansion
npm
Transitive 2.0.2 5.0.6 11 behind 1 medium MIT
brace-expansion
npm
Transitive 2.0.2 5.0.6 11 behind 1 medium MIT
brace-expansion
npm
Transitive 2.0.2 5.0.6 11 behind 1 medium MIT
pytest
pypi
Direct 8.3.4 9.0.3 8 behind 1 medium MIT
requests
pypi
Direct 2.32.4 2.34.2 7 behind 1 medium Apache-2.0
yaml
npm
Transitive 2.8.2 2.9.0 6 behind 1 medium ISC
python-dotenv
pypi
Direct 1.0.1 1.2.2 5 behind 1 medium BSD-2-Clause AND BSD-3-Clause
body-parser
npm
Transitive 2.2.0 2.2.2 3 behind 1 medium MIT
body-parser
npm
Transitive 2.2.0 2.2.2 3 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
follow-redirects
npm
Transitive 1.15.11 1.16.0 1 behind 1 medium MIT
follow-redirects
npm
Transitive 1.15.11 1.16.0 1 behind 1 medium MIT
mdast-util-to-hast
npm
Transitive 13.2.0 13.2.1 1 behind 1 medium MIT
@smithy/config-resolver
npm
Transitive 4.1.5 4.5.6 32 behind 1 low Apache-2.0
@smithy/config-resolver
npm
Transitive 4.1.5 4.5.6 32 behind 1 low Apache-2.0
diff
npm
Transitive 4.0.2 9.0.0 18 behind 1 low BSD-3-Clause
diff
npm
Transitive 4.0.2 9.0.0 18 behind 1 low BSD-3-Clause
@tootallnate/once
npm
Transitive 2.0.0 3.0.1 2 behind 1 low MIT
fs
npm
Direct 0.0.1-security 0.0.1-security Current 1 unknown ISC

License Breakdown

MIT 3750
Apache-2.0 671
Unknown 558
ISC 247
BSD-3-Clause 175
BSD-2-Clause 59
Apache-2.0 AND MIT 22
CC0-1.0 AND MIT 19
BSD-2-Clause AND BSD-3-Clause 16
LGPL-3.0-or-later 16
MIT OR Apache-2.0 16
BlueOak-1.0.0 12
ISC AND MIT 12
MPL-2.0 11
0BSD 8
Apache-2.0 AND BSD-2-Clause 7
BSD-3-Clause AND MIT 6
BSD-2-Clause AND BSD-2-Clause-Views 5
CC-BY-SA-4.0 AND ISC 5
CC0-1.0 5
Apache-2.0 AND LGPL-3.0-or-later 4
CC-BY-4.0 4
Python-2.0 4
BSD-3-Clause AND LicenseRef-scancode-protobuf 3
MIT AND MS-PL 3
Unlicense 3
0BSD AND ISC AND MIT 2
Apache-2.0 AND BSD-3-Clause 2
Apache-2.0 AND BSD-3-Clause AND MIT 2
Apache-2.0 AND LGPL-3.0-or-later AND MIT 2
Apache-2.0 AND LicenseRef-scancode-generic-cla 2
Apache-2.0 OR (Apache-2.0 AND LGPL-3.0-only) 2
Apache-2.0 OR MIT OR (Apache-2.0 AND MIT) 2
BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 2
BSD-3-Clause AND ISC AND MIT 2
(Apache-2.0 OR BSD-3-Clause) 1
0BSD AND Apache-2.0 AND Artistic-2.0 AND BSD-2-Clause AND BSD-3-Clause AND CC-BY-3.0 AND CC-BY-4.0 AND CC0-1.0 AND MIT AND Unlicense 1
0BSD AND MIT 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MIT AND MPL-2.0 1
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 1
Apache-2.0 AND CC-BY-3.0 AND CC-BY-4.0 AND CC-BY-SA-3.0 AND CC0-1.0 AND ISC AND LicenseRef-scancode-unknown-license-reference AND MIT AND MPL-2.0 AND OFL-1.1 1
Apache-2.0 AND CNRI-Python 1
Apache-2.0 AND ISC 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 1
Apache-2.0 OR MPL-2.0 1
BSD-2-Clause AND BSD-3-Clause AND MIT 1
BSD-3-Clause AND LicenseRef-scancode-generic-cla AND MIT 1
CNRI-Python AND Apache-2.0 1
LicenseRef-scancode-free-unknown AND MIT 1
LicenseRef-scancode-generic-cla AND MIT 1
LicenseRef-scancode-public-domain AND Unlicense 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
MIT AND MIT-0 1
MIT AND MITNFA 1
MIT AND MPL-2.0 1
MIT AND Python-2.0 1
MIT OR (CC0-1.0 AND MIT) 1
MIT OR (MIT AND WTFPL) 1
MIT OR WTFPL OR (MIT AND WTFPL) 1
PSF-2.0 1
Python-2.0.1 1

CVE Severity

critical 10
high 54
medium 33
low 5
unknown 1

Beta — feedback welcome: [email protected]