Skip to content
Tools / langchain / Dependencies

Dependency Analysis

langchain

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

47% Freshness
2448 Dependencies
1036 Outdated
0 Stale
4.0 Avg Behind

Dependency List

Latest release langchain-classic==1.0.6

Dependency Type Current Latest Behind CVE License
h11
pypi
Direct 0.14.0 0.16.0 2 behind 1 critical MIT
protobuf
pypi
Direct 4.25.5 7.35.0 45 behind 2 high BSD-3-Clause
setuptools
pypi
Direct 75.3.0 82.0.1 40 behind 1 high MIT
aiohttp
pypi
Direct 3.11.11 3.14.0 37 behind 19 high Apache-2.0
starlette
pypi
Direct 0.41.2 1.2.1 30 behind 2 high BSD-2-Clause AND BSD-3-Clause
orjson
pypi
Direct 3.10.10 3.11.9 18 behind 1 high Apache-2.0 AND MIT
urllib3
pypi
Direct 2.2.3 2.7.0 8 behind 5 high MIT
pillow
pypi
Direct 11.1.0 12.2.0 6 behind 5 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
mistune
pypi
Transitive 3.1.4 3.2.1 2 behind 1 high BSD-3-Clause
mistune
pypi
Transitive 3.1.4 3.2.1 2 behind 1 high BSD-3-Clause
mistune
pypi
Transitive 3.1.4 3.2.1 2 behind 1 high BSD-3-Clause
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
langsmith
pypi
Direct 0.1.139 0.8.9 228 behind 1 medium MIT
pytest
pypi
Direct 7.4.4 9.0.3 24 behind 1 medium MIT
filelock
pypi
Direct 3.16.1 3.29.1 23 behind 2 medium Unlicense
requests
pypi
Direct 2.32.3 2.34.2 8 behind 2 medium Apache-2.0
python-dotenv
pypi
Direct 1.0.1 1.2.2 5 behind 1 medium BSD-2-Clause AND BSD-3-Clause
pygments
pypi
Direct 2.18.0 2.20.0 4 behind 1 low BSD-2-Clause

License Breakdown

MIT 877
Unknown 333
Apache-2.0 329
BSD-3-Clause 249
BSD-2-Clause AND BSD-3-Clause 133
BSD-2-Clause 80
MPL-2.0 61
Apache-2.0 AND MIT 40
MIT AND Python-2.0 26
Apache-2.0 AND BSD-2-Clause 25
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 21
Apache-2.0 AND MIT AND MPL-2.0 21
Apache-2.0 AND Python-2.0 21
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 21
MIT-0 20
CC-BY-3.0 AND MIT 19
ISC 17
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 15
MIT AND Python-2.0 AND Python-2.0.1 14
LicenseRef-scancode-generic-cla AND MIT 12
BSD-2-Clause AND MIT AND Python-2.0 AND Python-2.0.1 9
BSD-3-Clause AND MIT 9
CNRI-Python AND Apache-2.0 8
PSF-2.0 8
Unlicense 8
MIT-CMU 7
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 6
BSD-2-Clause AND BSD-3-Clause AND MIT 6
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 5
(Apache-2.0 AND BSD-3-Clause AND MIT) OR (Apache-2.0 AND MIT) 4
BSD-2-Clause AND MIT AND Python-2.0.1 4
BSD-3-Clause AND LicenseRef-scancode-protobuf 4
CC-BY-4.0 AND LicenseRef-scancode-public-domain AND MIT 4
MIT AND MPL-2.0 4
Apache-2.0 AND GPL-1.0-or-later AND MIT 3
BSD-2-Clause AND BSD-3-Clause AND ISC AND Python-2.0 3
BSD-2-Clause AND BSD-3-Clause AND MIT AND Python-2.0 AND Ruby 3
BSD-3-Clause AND CC0-1.0 AND ISC AND MIT 3
GPL-3.0-only AND GPL-3.0-or-later AND MIT 3
MIT AND CC0-1.0 3
MIT AND PSF-2.0 AND Python-2.0 3
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 2
BSD-3-Clause OR Apache-2.0 2
MIT AND ZPL-2.1 2
Apache-2.0 AND BSD-3-Clause 1
Apache-2.0 AND CC-BY-NC-4.0 AND LicenseRef-scancode-unknown-license-reference 1
BSD-2-Clause AND BSD-3-Clause AND Python-2.0 AND Ruby 1
GPL-2.0 AND GPL-2.0-only 1
GPL-3.0-or-later 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
Python-2.0.1 1

CVE Severity

critical 1
high 11
medium 5
low 1
unknown 0

Beta — feedback welcome: [email protected]