Skip to content
Tools / Kometa / Dependencies

Dependency Analysis

Kometa

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

86% Freshness
60 Dependencies
4 Outdated
0 Stale
0.8 Avg Behind

Dependency List

Latest release v2.3.1

Dependency Type Current Latest Behind CVE License
gitpython
pypi
Direct 3.1.46 3.1.50 4 behind 4 high BSD-3-Clause
lxml
pypi
Direct 6.0.2 6.1.1 4 behind 1 high BSD-3-Clause AND GPL-1.0-or-later
pillow
pypi
Direct 12.1.1 12.2.0 1 behind 5 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
prek
pypi
Direct 0.3.8 0.4.3 9 behind MIT
mypy
pypi
Direct 1.20.0 2.1.0 4 behind MIT AND Python-2.0 AND Python-2.0.1 AND BSD-2-Clause AND MIT AND Python-2.0 AND Python-2.0.1 AND BSD-2-Clause
requests
pypi
Direct 2.33.1 2.34.2 4 behind Apache-2.0
black
pypi
Direct 26.3.1 26.5.1 2 behind MIT

License Breakdown

Unknown 36
MIT 10
Apache-2.0 3
BSD-3-Clause 3
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause AND GPL-1.0-or-later 1
LGPL-2.1-only AND LGPL-3.0-or-later 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
MIT AND Python-2.0 AND Python-2.0.1 AND BSD-2-Clause AND MIT AND Python-2.0 AND Python-2.0.1 AND BSD-2-Clause 1
PSF-2.0 1

CVE Severity

critical 0
high 3
medium 0
low 0
unknown 0

Beta — feedback welcome: [email protected]