Skip to content
Tools / kinto / Dependencies

Dependency Analysis

kinto

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

76% Freshness
237 Dependencies
46 Outdated
0 Stale
2.1 Avg Behind

Dependency List

Latest release 26.1.0

Dependency Type Current Latest Behind CVE License
h11
pypi
Direct 0.14.0 0.16.0 2 behind 1 critical MIT
waitress
pypi
Direct 2.1.2 2 critical ZPL-2.1
werkzeug
pypi
Direct 3.0.1 3.1.8 15 behind 6 high BSD-2-Clause AND BSD-3-Clause
httpie
pypi
Direct 3.2.4 1 high BSD-2-Clause AND BSD-3-Clause
selenium
pypi
Direct 4.12.0 1 high Apache-2.0
urllib3
pypi
Direct 2.1.0 5 high MIT
pytest
pypi
Direct 7.4.4 9.0.3 24 behind 1 medium MIT
requests
pypi
Direct 2.31.0 2.34.2 12 behind 3 medium Apache-2.0
pip
pypi
Transitive 26.0.1 26.1.2 3 behind 2 medium MIT
idna
pypi
Direct 3.6 3.18.0 1 medium BSD-3-Clause
webob
pypi
Direct 1.8.7 1 medium MIT
zipp
pypi
Direct 3.17.0 1 medium MIT
certifi
pypi
Direct 2023.11.17 1 low MPL-2.0
sqlalchemy
pypi
Direct 2.0.25 2.0.50 31 behind MIT
google-auth
pypi
Transitive 2.48.0 3.0.0.dev0 21 behind Apache-2.0
sentry-sdk
pypi
Direct 2.53.0 2.61.1 16 behind Unknown
beautifulsoup4
pypi
Direct 4.12.3 4.14.3 12 behind MIT
trio
pypi
Direct 0.24.0 0.33.0 12 behind Apache-2.0 OR (Apache-2.0 AND MIT)
protobuf
pypi
Transitive 6.33.5 7.35.0 9 behind BSD-3-Clause AND LicenseRef-scancode-protobuf
pytest-cov
pypi
Direct 4.1.0 7.1.0 9 behind MIT
ty
pypi
Direct 0.0.33 0.0.42 9 behind Unknown
attrs
pypi
Direct 23.2.0 26.1.0 8 behind MIT
charset-normalizer
pypi
Direct 3.3.2 3.4.7 8 behind LGPL-2.1-only AND MIT AND MPL-1.1
jsonschema
pypi
Direct 4.21.1 4.26.0 7 behind MIT
simplejson
pypi
Direct 3.19.2 4.1.1 6 behind MIT AND AFL-3.0
tomli
pypi
Direct 2.0.1 2.4.1 6 behind MIT
greenlet
pypi
Transitive 3.3.1 3.5.1 5 behind MIT AND PSF-2.0
click
pypi
Transitive 8.3.1 8.4.1 4 behind BSD-3-Clause
google-api-core
pypi
Transitive 2.30.0 2.31.0 4 behind Apache-2.0
google-resumable-media
pypi
Transitive 2.8.0 2.10.0 4 behind Apache-2.0
googleapis-common-protos
pypi
Transitive 1.72.0 1.75.0 4 behind Apache-2.0
more-itertools
pypi
Transitive 10.8.0 11.1.0 4 behind MIT
requests
pypi
Direct 2.33.1 2.34.2 4 behind Apache-2.0
certifi
pypi
Transitive 2026.1.4 2026.5.20 3 behind MPL-2.0
charset-normalizer
pypi
Transitive 3.4.4 3.4.7 3 behind MIT
coverage
pypi
Transitive 7.13.4 7.14.1 3 behind Apache-2.0
iniconfig
pypi
Direct 2.0.0 2.3.0 3 behind MIT
jsonschema-specifications
pypi
Direct 2023.12.1 2025.9.1 3 behind MIT
pluggy
pypi
Direct 1.3.0 1.6.0 3 behind MIT
pyyaml
pypi
Direct 6.0.1 6.0.3 3 behind MIT
redis
pypi
Direct 7.4.0 8.0.0 3 behind Unknown
rich
pypi
Transitive 14.3.2 15.0.0 3 behind MIT
ruff
pypi
Direct 0.15.12 0.15.15 3 behind MIT
setuptools
pypi
Direct 81.0.0 82.0.1 3 behind MIT
simplejson
pypi
Transitive 3.20.2 4.1.1 3 behind (AFL-2.1 AND MIT AND Python-2.0) OR (AFL-2.1 AND MIT)
trio-websocket
pypi
Direct 0.11.1 0.12.2 3 behind MIT
wsproto
pypi
Direct 1.2.0 1.3.2 3 behind MIT
cryptography
pypi
Transitive 46.0.7 48.0.0 2 behind BSD-3-Clause OR Apache-2.0
docutils
pypi
Direct 0.22.4 0.23.0 2 behind BSD-2-Clause AND BSD-3-Clause AND CC-PDDC AND GPL-1.0-or-later AND GPL-3.0-only AND GPL-3.0-or-later AND LicenseRef-scancode-free-unknown AND LicenseRef-scancode-other-copyleft AND LicenseRef-scancode-public-domain
google-cloud-core
pypi
Transitive 2.5.0 2.6.0 2 behind Apache-2.0
google-cloud-storage
pypi
Transitive 3.9.0 3.10.1 2 behind Apache-2.0
importlib-metadata
pypi
Transitive 8.7.1 9.0.0 2 behind Apache-2.0
importlib-resources
pypi
Transitive 6.5.2 7.1.0 2 behind Apache-2.0
jaraco-context
pypi
Transitive 6.1.0 6.1.2 2 behind Unknown
jsonpointer
pypi
Transitive 3.0.0 3.1.1 2 behind BSD-3-Clause
markdown-it-py
pypi
Transitive 4.0.0 4.2.0 2 behind MIT
nh3
pypi
Transitive 0.3.3 0.3.5 2 behind MIT
proto-plus
pypi
Transitive 1.27.1 1.28.0 2 behind Apache-2.0
pyproject-hooks
pypi
Direct 1.0.0 1.2.0 2 behind MIT
python-dateutil
pypi
Direct 2.8.2 2.9.0.post0 2 behind Apache-2.0
sqlalchemy
pypi
Direct 2.0.49 2.0.50 2 behind MIT
zipp
pypi
Transitive 3.23.0 4.1.0 2 behind MIT
arrow
pypi
Direct 1.3.0 1.4.0 1 behind Apache-2.0
attrs
pypi
Transitive 25.4.0 26.1.0 1 behind MIT
jaraco-functools
pypi
Transitive 4.4.0 4.5.0 1 behind Unknown
playwright
pypi
Direct 1.59.0 1.60.0 1 behind Unknown
rpds-py
pypi
Transitive 0.30.0 2026.5.1 1 behind MIT
six
pypi
Direct 1.16.0 1.17.0 1 behind MIT
soupsieve
pypi
Transitive 2.8.3 2.8.4 1 behind MIT
tomli
pypi
Transitive 2.4.0 2.4.1 1 behind MIT
urllib3
pypi
Transitive 2.6.3 2.7.0 1 behind MIT
actions/cache
githubactions
Direct 5.*.* Unknown
actions/checkout
githubactions
Direct 6.*.* Unknown
actions/download-artifact
githubactions
Direct 8.*.* Unknown
actions/setup-node
githubactions
Direct 6.*.* Unknown
actions/upload-artifact
githubactions
Direct 7.*.* Unknown
arrow
pypi
Transitive 1.4.0 1.4.0 Current Apache-2.0
astral-sh/setup-uv
githubactions
Direct 7.*.* Unknown
async-timeout
pypi
Transitive 5.0.1 5.0.1 Current Apache-2.0
backports-tarfile
pypi
Transitive 1.2.0 1.2.0 Current Unknown
bcrypt
pypi
Direct 5.0.0 5.0.0 Current Apache-2.0
bcrypt
pypi
Direct 4.1.2 Apache-2.0
beautifulsoup4
pypi
Transitive 4.14.3 4.14.3 Current MIT
bravado
pypi
Direct 12.0.1 BSD-3-Clause
bravado-core
pypi
Transitive 6.1.1 BSD-3-Clause
build
pypi
Direct 1.5.0 1.5.0 Current Unknown
build
pypi
Direct 1.0.3 MIT
cffi
pypi
Transitive 2.0.0 2.0.0 Current MIT-0
colander
pypi
Direct 2.0 BSD-2-Clause AND BSD-3-Clause-Modification
colorama
pypi
Transitive 0.4.6 0.4.6 Current BSD-2-Clause AND BSD-3-Clause
cornice
pypi
Direct 6.0.1 MPL-2.0
cornice-swagger
pypi
Direct 1.0.1 Apache-2.0
coverage
pypi
Direct 7.4.0 Apache-2.0
defusedxml
pypi
Transitive 0.7.1 0.7.1 Current PSF-2.0
docker/build-push-action
githubactions
Direct 7.*.* Unknown
docker/login-action
githubactions
Direct 4.*.* Unknown
docker/metadata-action
githubactions
Direct 6.*.* Unknown
docker/setup-buildx-action
githubactions
Direct 4.*.* Unknown
docker/setup-qemu-action
githubactions
Direct 4.*.* Unknown
dockerflow
pypi
Direct 2026.3.4 Unknown
dockerflow
pypi
Direct 2024.1.0 MPL-2.0
exceptiongroup
pypi
Transitive 1.3.1 1.3.1 Current MIT AND Python-2.0
exceptiongroup
pypi
Direct 1.2.0 MIT
execnet
pypi
Transitive 2.1.2 2.1.2 Current MIT
execnet
pypi
Direct 2.0.2 MIT
fqdn
pypi
Direct 1.5.1 1.5.1 Current MPL-2.0
google-crc32c
pypi
Transitive 1.8.0 1.8.0 Current Apache-2.0
granian
pypi
Direct 2.7.4 Unknown
hatchling
Direct Unknown
hupper
pypi
Transitive 1.12.1 MIT
hupper
pypi
Direct 1.12 MIT
id
pypi
Transitive 1.6.1 1.6.1 Current Apache-2.0
idna
pypi
Transitive 3.11 3.18.0 BSD-3-Clause
importlib-metadata
pypi
Direct 7.0.1 Apache-2.0
iniconfig
pypi
Transitive 2.3.0 2.3.0 Current MIT
iso8601
pypi
Transitive 2.1.0 MIT
isoduration
pypi
Direct 20.11.0 20.11.0 Current ISC
jaraco-classes
pypi
Transitive 3.4.0 3.4.0 Current Unknown
jeepney
pypi
Transitive 0.9.0 0.9.0 Current MIT
jsonpatch
pypi
Direct 1.33 1.33.0 BSD-3-Clause
jsonpointer
pypi
Direct 2.4 3.1.1 BSD-3-Clause
jsonref
pypi
Transitive 1.1.0 1.1.0 Current MIT
jsonschema
pypi
Direct 4.26.0 4.26.0 Current MIT
jsonschema-specifications
pypi
Transitive 2025.9.1 2025.9.1 Current MIT
keyring
pypi
Transitive 25.7.0 25.7.0 Current MIT
kinto
Direct Unknown
kinto
Direct Unknown
kinto-attachment
pypi
Direct 8.0.0 Unknown
kinto-emailer
pypi
Direct 3.0.4 Apache-2.0
lark
pypi
Transitive 1.3.1 1.3.1 Current MIT AND MPL-2.0
legacy-cgi
pypi
Transitive 2.6.4 2.6.4 Current Python-2.0 AND Python-2.0 AND BSD-3-Clause AND Python-2.0.1
logging-color-formatter
pypi
Direct 1.1.0 Apache-2.0
ludeeus/action-shellcheck
githubactions
Direct master Unknown
markupsafe
pypi
Transitive 3.0.3 3.0.3 Current BSD-3-Clause
markupsafe
pypi
Direct 2.1.4 BSD-2-Clause AND BSD-3-Clause
mdurl
pypi
Transitive 0.1.2 0.1.2 Current MIT
mock
pypi
Direct 5.2.0 5.2.0 Current BSD-2-Clause AND BSD-3-Clause
mock
pypi
Direct 5.2.0 5.2.0 Current BSD-2-Clause AND BSD-3-Clause
monotonic
pypi
Transitive 1.6 1.6.0 Apache-2.0
msgpack
pypi
Transitive 1.1.2 1.1.2 Current Apache-2.0
msgpack
pypi
Direct 1.0.7 Apache-2.0
multidict
pypi
Transitive 6.7.1 6.7.1 Current Apache-2.0
newrelic
pypi
Direct 12.1.0 Unknown
newrelic
pypi
Direct 9.5.0 Apache-2.0
outcome
pypi
Direct 1.3.0.post0 1.3.0.post0 Current Apache-2.0 OR (Apache-2.0 AND MIT)
packaging
pypi
Transitive 26.0 26.2.0 Apache-2.0 AND BSD-2-Clause
packaging
pypi
Direct 23.2 26.2.0 Apache-2.0 AND BSD-2-Clause
pastedeploy
pypi
Transitive 3.1.0 MIT
plaster
pypi
Transitive 1.1.2 MIT
plaster-pastedeploy
pypi
Transitive 1.0.1 MIT
pluggy
pypi
Transitive 1.6.0 1.6.0 Current MIT
prometheus-client
pypi
Direct 0.25.0 0.25.0 Current Apache-2.0 AND BSD-2-Clause
psycopg2
pypi
Direct 2.9.9 LGPL-3.0-or-later WITH openvpn-openssl-exception
psycopg2-binary
pypi
Direct 2.9.12 2.9.12 Current LGPL-2.0-or-later AND LGPL-3.0-or-later
pyasn1
pypi
Transitive 0.6.3 0.6.3 Current BSD-2-Clause AND BSD-3-Clause AND MIT
pyasn1-modules
pypi
Transitive 0.4.2 0.4.2 Current BSD-2-Clause AND BSD-3-Clause
pycparser
pypi
Transitive 3.0 3.0.0 BSD-3-Clause
pyee
pypi
Transitive 13.0.1 13.0.1 Current MIT
pygments
pypi
Transitive 2.20.0 2.20.0 Current BSD-2-Clause
pypa/gh-action-pypi-publish
githubactions
Direct release/v1 Unknown
pyproject-hooks
pypi
Transitive 1.2.0 1.2.0 Current MIT
pyramid
pypi
Direct 2.1 Unknown
pyramid
pypi
Direct 2.0.2 Unknown
pyramid-mailer
pypi
Transitive 0.15.1 BSD-2-Clause AND BSD-3-Clause
pyramid-multiauth
pypi
Direct 1.0.2 AGPL-3.0-or-later AND MPL-2.0
pyramid-multiauth
pypi
Direct 1.0.1 MPL-2.0
pyramid-tm
pypi
Direct 2.6 BSD-2-Clause
pyramid-tm
pypi
Direct 2.5 BSD-3-Clause-Modification
pysocks
pypi
Direct 1.7.1 1.7.1 Current BSD-3-Clause
pytest
pypi
Direct 9.0.3 9.0.3 Current MIT
pytest-cache
pypi
Direct 1.0 MIT
pytest-cov
pypi
Direct 7.1.0 7.1.0 Current MIT
pytest-xdist
pypi
Direct 3.8.0 3.8.0 Current MIT
python-dateutil
pypi
Direct 2.9.0.post0 2.9.0.post0 Current Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference
python-memcached
pypi
Direct 1.62 Python-2.0
python-rapidjson
pypi
Direct 1.23 1.23.0 MIT
python-rapidjson
pypi
Direct 1.14 MIT
pytz
pypi
Transitive 2025.2 2026.2.0 MIT AND ZPL-2.1
pytz
pypi
Direct 2023.3.post1 2026.2.0 MIT
pywin32-ctypes
pypi
Transitive 0.2.3 0.2.3 Current BSD-3-Clause
pyyaml
pypi
Transitive 6.0.3 6.0.3 Current MIT
raven-actions/actionlint
githubactions
Direct 2.*.* Unknown
readme-renderer
pypi
Transitive 44.0 44.0.0 Apache-2.0
referencing
pypi
Transitive 0.37.0 0.37.0 Current MIT
referencing
pypi
Direct 0.32.1 MIT
repoze-sendmail
pypi
Transitive 4.4.1 Unknown
requests-toolbelt
pypi
Transitive 1.0.0 1.0.0 Current Apache-2.0
rfc3339-validator
pypi
Direct 0.1.4 0.1.4 Current MIT
rfc3986
pypi
Transitive 2.0.0 2.0.0 Current Apache-2.0
rfc3986-validator
pypi
Direct 0.1.1 0.1.1 Current MIT
rfc3987-syntax
pypi
Direct 1.1.0 1.1.0 Current Apache-2.0 AND GPL-1.0-or-later AND MIT
rpds-py
pypi
Direct 0.17.1 MIT
rsa
pypi
Transitive 4.9.1 4.9.1 Current Apache-2.0
ruff
pypi
Direct 0.1.14 MIT
secretstorage
pypi
Transitive 3.5.0 3.5.0 Current BSD-3-Clause
sentry-sdk
Direct Unknown
sentry-sdk
pypi
Direct 1.39.2 BSD-2-Clause AND MIT
setuptools
Direct < 82.0 Unknown
six
pypi
Transitive 1.17.0 1.17.0 Current MIT
sniffio
pypi
Direct 1.3.0 Apache-2.0
sortedcontainers
pypi
Direct 2.4.0 2.4.0 Current Apache-2.0
soupsieve
pypi
Direct 2.5 2.8.4 MIT
sphinx
pypi
Direct 9.1.0 9.1.0 Current Unknown
sphinx
pypi
Direct 9.1.0 9.1.0 Current Unknown
sphinx-github-changelog
pypi
Direct 1.7.2 Unknown
sphinx-github-changelog
pypi
Direct 1.7.2 Unknown
sphinx-rtd-theme
pypi
Direct 3.1.0 3.1.0 Current MIT AND OFL-1.1
sphinx-rtd-theme
pypi
Direct 3.1.0 3.1.0 Current MIT AND OFL-1.1
sphinxcontrib-httpdomain
pypi
Direct 2.0.0 Unknown
sphinxcontrib-httpdomain
pypi
Direct 2.0.0 Unknown
statsd
pypi
Direct 4.0.1 MIT
swagger-spec-validator
pypi
Transitive 3.0.4 Apache-2.0
swagger-spec-validator
pypi
Direct 3.0.3 Apache-2.0
transaction
pypi
Direct 5.1 Unknown
transaction
pypi
Direct 4.0 ZPL-2.1
translationstring
pypi
Transitive 1.4 ZPL-2.0
twine
pypi
Direct 6.2.0 6.2.0 Current Apache-2.0
types-python-dateutil
pypi
Direct 2.8.19.20240106 Apache-2.0
typing-extensions
pypi
Transitive 4.15.0 4.15.0 Current Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD
typing-extensions
pypi
Direct 4.9.0 Python-2.0.1
tzdata
pypi
Transitive 2025.3 2026.2.0 Apache-2.0
uri-template
pypi
Direct 1.3.0 1.3.0 Current MIT
uv-dynamic-versioning
Direct Unknown
venusian
pypi
Transitive 3.1.1 BSD-2-Clause
venusian
pypi
Direct 3.1.0 BSD-3-Clause-Modification
waitress
pypi
Direct 3.0.2 3.0.2 Current ZPL-2.1
webcolors
pypi
Direct 25.10.0 25.10.0 Current BSD-3-Clause
webcolors
pypi
Direct 1.13 BSD-2-Clause AND BSD-3-Clause
webob
pypi
Transitive 1.8.9 MIT
webtest
pypi
Direct 3.0.7 MIT
webtest
pypi
Direct 3.0.0 MIT
werkzeug
pypi
Direct 3.1.8 3.1.8 Current BSD-3-Clause
zope-deprecation
pypi
Transitive 6.0 Unknown
zope-deprecation
pypi
Direct 5.0 ZPL-2.1
zope-interface
pypi
Transitive 8.2 8.5.0 Unknown
zope-interface
pypi
Direct 6.1 Unknown
zope-sqlalchemy
pypi
Direct 4.1 Unknown
zope-sqlalchemy
pypi
Direct 3.1 Unknown

License Breakdown

MIT 76
Unknown 48
Apache-2.0 42
BSD-3-Clause 15
BSD-2-Clause AND BSD-3-Clause 9
MPL-2.0 6
ZPL-2.1 4
Apache-2.0 AND BSD-2-Clause 3
BSD-2-Clause 3
Apache-2.0 OR (Apache-2.0 AND MIT) 2
BSD-3-Clause-Modification 2
MIT AND OFL-1.1 2
(AFL-2.1 AND MIT AND Python-2.0) OR (AFL-2.1 AND MIT) 1
AGPL-3.0-or-later AND MPL-2.0 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND GPL-1.0-or-later AND MIT 1
BSD-2-Clause AND BSD-3-Clause AND CC-PDDC AND GPL-1.0-or-later AND GPL-3.0-only AND GPL-3.0-or-later AND LicenseRef-scancode-free-unknown AND LicenseRef-scancode-other-copyleft AND LicenseRef-scancode-public-domain 1
BSD-2-Clause AND BSD-3-Clause AND MIT 1
BSD-2-Clause AND BSD-3-Clause-Modification 1
BSD-2-Clause AND MIT 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
BSD-3-Clause OR Apache-2.0 1
ISC 1
LGPL-2.0-or-later AND LGPL-3.0-or-later 1
LGPL-2.1-only AND MIT AND MPL-1.1 1
LGPL-3.0-or-later WITH openvpn-openssl-exception 1
MIT AND AFL-3.0 1
MIT AND MPL-2.0 1
MIT AND PSF-2.0 1
MIT AND Python-2.0 1
MIT AND ZPL-2.1 1
MIT-0 1
PSF-2.0 1
Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Python-2.0 AND Python-2.0 AND BSD-3-Clause AND Python-2.0.1 1
Python-2.0.1 1
ZPL-2.0 1

CVE Severity

critical 2
high 4
medium 6
low 1
unknown 0

Beta — feedback welcome: [email protected]