Skip to content
Tools / LightRAG / Dependencies

Dependency Analysis

LightRAG

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

48% Freshness
437 Dependencies
177 Outdated
0 Stale
8.2 Avg Behind

Dependency List

Latest release v1.5.0rc1

Dependency Type Current Latest Behind CVE License
langchain-core
pypi
Direct 1.0.4 1.4.0 56 behind 5 critical MIT
nltk
pypi
Direct 3.9.2 3.9.4 2 behind 7 critical Apache-2.0
protobuf
pypi
Direct 6.33.0 7.35.0 15 behind 1 high BSD-3-Clause AND LicenseRef-scancode-protobuf
langchain-community
pypi
Direct 0.3.21 0.4.2 14 behind 1 high MIT
python-multipart
pypi
Direct 0.0.20 0.0.30 10 behind 3 high Apache-2.0
pyjwt
pypi
Direct 2.8.0 2.13.0 7 behind 1 high MIT
cryptography
pypi
Direct 46.0.3 48.0.0 6 behind 3 high BSD-3-Clause OR Apache-2.0
gitpython
pypi
Direct 3.1.45 3.1.50 5 behind 4 high BSD-3-Clause
orjson
pypi
Direct 3.11.4 3.11.9 5 behind 1 high Apache-2.0 AND MIT
urllib3
pypi
Direct 2.5.0 2.7.0 5 behind 3 high MIT
aiohttp
pypi
Direct 3.13.2 3.14.0 4 behind 18 high Apache-2.0 AND MIT
banks
pypi
Direct 2.2.0 2.4.2 4 behind 1 high MIT
lxml
pypi
Direct 6.0.2 6.1.1 4 behind 1 high BSD-3-Clause AND GPL-1.0-or-later
pillow
pypi
Direct 11.3.0 12.2.0 4 behind 6 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
ujson
pypi
Direct 5.11.0 5.12.1 2 behind 2 high BSD-3-Clause AND TCL
ecdsa
pypi
Direct 0.19.1 0.19.2 1 behind 2 high LicenseRef-scancode-public-domain AND MIT
langsmith
pypi
Direct 0.4.38 0.8.9 90 behind 2 medium MIT
langgraph
pypi
Direct 1.0.2 1.2.4 34 behind 1 medium MIT
transformers
pypi
Direct 4.57.1 5.10.1 28 behind 1 medium Apache-2.0
filelock
pypi
Direct 3.20.0 3.29.1 19 behind 2 medium Unlicense
virtualenv
pypi
Direct 20.35.4 21.4.2 19 behind 1 medium MIT
langgraph-checkpoint
pypi
Direct 3.0.1 4.1.1 13 behind 1 medium MIT
marshmallow
pypi
Direct 3.26.1 4.3.0 12 behind 1 medium BSD-3-Clause AND MIT
requests
pypi
Direct 2.32.5 2.34.2 6 behind 1 medium Apache-2.0
langchain-text-splitters
pypi
Direct 0.3.11 1.1.2 5 behind 1 medium MIT
pytest
pypi
Direct 8.4.2 9.0.3 4 behind 1 medium MIT
python-dotenv
pypi
Direct 1.2.1 1.2.2 1 behind 1 medium BSD-3-Clause
diskcache
pypi
Direct 5.6.3 5.6.3 Current 1 medium Apache-2.0
langchain-openai
pypi
Direct 0.3.35 1.2.2 25 behind 1 low MIT
ragas
pypi
Direct 0.3.8 0.4.3 5 behind 1 low Apache-2.0
pygments
pypi
Direct 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause

License Breakdown

Unknown 173
MIT 119
Apache-2.0 53
BSD-3-Clause 27
BSD-2-Clause AND BSD-3-Clause 14
Apache-2.0 AND MIT 6
BSD-2-Clause 6
BSD-2-Clause AND BSD-3-Clause AND MIT 2
ISC 2
MPL-2.0 2
PSF-2.0 2
(Apache-2.0 AND BSD-3-Clause AND LicenseRef-PdfiumThirdParty) OR (Apache-2.0 AND LicenseRef-PdfiumThirdParty) OR (BSD-3-Clause AND LicenseRef-PdfiumThirdParty) 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 1
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND MIT AND MPL-2.0 1
BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain AND Unlicense 1
BSD-3-Clause AND GPL-1.0-or-later 1
BSD-3-Clause AND LGPL-2.1-only 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
BSD-3-Clause AND MIT 1
BSD-3-Clause AND TCL 1
BSD-3-Clause OR Apache-2.0 1
BSL-1.0 AND MIT 1
CNRI-Python AND Apache-2.0 1
ISC AND MPL-2.0 1
LicenseRef-scancode-free-unknown AND MIT 1
LicenseRef-scancode-public-domain AND MIT 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
MIT AND AFL-3.0 1
MIT AND PSF-2.0 AND Python-2.0 1
MIT AND Python-2.0 1
MIT AND ZPL-2.1 1
MIT-0 1
PSF-2.0 AND Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Unlicense 1

CVE Severity

critical 2
high 15
medium 12
low 3
unknown 0

Beta — feedback welcome: [email protected]