Skip to content
Tools / LightRAG / Dependencies

Dependency Analysis

LightRAG

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

48% Freshness
437 Dependencies
177 Outdated
0 Stale
8.2 Avg Behind

Dependency List

Latest release v1.5.0rc1

Dependency Type Current Latest Behind CVE License
langchain-core
pypi
Direct 1.0.4 1.4.0 56 behind 5 critical MIT
nltk
pypi
Direct 3.9.2 3.9.4 2 behind 7 critical Apache-2.0
protobuf
pypi
Direct 6.33.0 7.35.0 15 behind 1 high BSD-3-Clause AND LicenseRef-scancode-protobuf
langchain-community
pypi
Direct 0.3.21 0.4.2 14 behind 1 high MIT
python-multipart
pypi
Direct 0.0.20 0.0.30 10 behind 3 high Apache-2.0
pyjwt
pypi
Direct 2.8.0 2.13.0 7 behind 1 high MIT
cryptography
pypi
Direct 46.0.3 48.0.0 6 behind 3 high BSD-3-Clause OR Apache-2.0
gitpython
pypi
Direct 3.1.45 3.1.50 5 behind 4 high BSD-3-Clause
orjson
pypi
Direct 3.11.4 3.11.9 5 behind 1 high Apache-2.0 AND MIT
urllib3
pypi
Direct 2.5.0 2.7.0 5 behind 3 high MIT
aiohttp
pypi
Direct 3.13.2 3.14.0 4 behind 18 high Apache-2.0 AND MIT
banks
pypi
Direct 2.2.0 2.4.2 4 behind 1 high MIT
lxml
pypi
Direct 6.0.2 6.1.1 4 behind 1 high BSD-3-Clause AND GPL-1.0-or-later
pillow
pypi
Direct 11.3.0 12.2.0 4 behind 6 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
ujson
pypi
Direct 5.11.0 5.12.1 2 behind 2 high BSD-3-Clause AND TCL
ecdsa
pypi
Direct 0.19.1 0.19.2 1 behind 2 high LicenseRef-scancode-public-domain AND MIT
langsmith
pypi
Direct 0.4.38 0.8.8 89 behind 2 medium MIT
langgraph
pypi
Direct 1.0.2 1.2.4 34 behind 1 medium MIT
transformers
pypi
Direct 4.57.1 5.9.0 26 behind 1 medium Apache-2.0
filelock
pypi
Direct 3.20.0 3.29.1 19 behind 2 medium Unlicense
virtualenv
pypi
Direct 20.35.4 21.4.2 19 behind 1 medium MIT
langgraph-checkpoint
pypi
Direct 3.0.1 4.1.1 13 behind 1 medium MIT
marshmallow
pypi
Direct 3.26.1 4.3.0 12 behind 1 medium BSD-3-Clause AND MIT
requests
pypi
Direct 2.32.5 2.34.2 6 behind 1 medium Apache-2.0
langchain-text-splitters
pypi
Direct 0.3.11 1.1.2 5 behind 1 medium MIT
pytest
pypi
Direct 8.4.2 9.0.3 4 behind 1 medium MIT
python-dotenv
pypi
Direct 1.2.1 1.2.2 1 behind 1 medium BSD-3-Clause
langchain-openai
pypi
Direct 0.3.35 1.2.2 25 behind 1 low MIT
ragas
pypi
Direct 0.3.8 0.4.3 5 behind 1 low Apache-2.0
pygments
pypi
Direct 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause
boto3
pypi
Direct 1.40.49 1.43.20 152 behind Apache-2.0
botocore
pypi
Direct 1.40.49 1.43.20 152 behind Apache-2.0 AND MIT AND MPL-2.0
langsmith
pypi
Direct 0.3.45 0.8.8 130 behind MIT
huggingface-hub
pypi
Direct 0.36.0 1.17.0 72 behind Apache-2.0
langchain-core
pypi
Direct 0.3.79 1.4.0 64 behind MIT
langchain
pypi
Direct 0.3.27 1.3.4 60 behind MIT
fastapi
pypi
Direct 0.120.2 0.136.3 55 behind MIT
ty
pypi
Direct 0.0.1a26 0.0.42 50 behind MIT
langfuse
pypi
Direct 3.9.1 4.7.1 48 behind Unknown
docling-core
pypi
Direct 2.51.0 3.0.0 46 behind MIT
anthropic
pypi
Direct 0.72.0 0.105.2 41 behind Unknown
docling
pypi
Direct 2.61.2 2.96.1 39 behind MIT
llama-cloud-services
pypi
Direct 0.6.54 0.6.94 39 behind MIT
llama-parse
pypi
Direct 0.6.54 0.6.94 39 behind MIT
google-genai
pypi
Direct 1.49.0 2.8.0 38 behind Unknown
langchain
pypi
Direct 1.0.5 1.3.4 36 behind MIT
faker
pypi
Direct 38.0.0 40.21.0 35 behind MIT
llama-cloud
pypi
Direct 0.1.35 2.8.0 35 behind MIT
openai
pypi
Direct 2.7.2 2.40.0 34 behind Apache-2.0
json-repair
pypi
Direct 0.52.3 0.59.10 33 behind Unknown
llama-index-workflows
pypi
Direct 2.9.1 2.20.0 33 behind Unknown
wrapt
pypi
Direct 1.17.3 2.2.1 33 behind BSD-2-Clause
numpy
pypi
Direct 1.26.4 2.4.6 28 behind BSD-2-Clause AND BSD-3-Clause
docling-parse
pypi
Direct 4.7.1 6.2.0 26 behind MIT
pypdf
pypi
Direct 6.1.3 6.12.2 26 behind Unknown
llama-index-llms-openai
pypi
Direct 0.6.12 0.7.9 24 behind MIT
ruff
pypi
Direct 0.14.6 0.15.15 24 behind MIT
langgraph-sdk
pypi
Direct 0.2.9 0.4.2 23 behind MIT
typer
pypi
Direct 0.19.2 0.26.7 22 behind MIT
langchain-openai
pypi
Direct 1.0.2 1.2.2 21 behind MIT
nvidia-cudnn-cu12
pypi
Direct 9.10.2.21 9.23.0.39 19 behind Unknown
ascii-colors
pypi
Direct 0.11.4 0.11.22 17 behind Apache-2.0
cachetools
pypi
Direct 6.2.1 7.1.4 17 behind MIT
qdrant-client
pypi
Direct 1.12.1 1.18.0 17 behind Apache-2.0
semchunk
pypi
Direct 2.2.2 4.0.0 16 behind MIT
aiobotocore
pypi
Direct 2.25.0 3.7.0 15 behind Apache-2.0
llama-index-core
pypi
Direct 0.14.6 0.14.22 15 behind Unknown
mpmath
pypi
Direct 1.3.0 1.4.1 15 behind BSD-3-Clause
pymilvus
pypi
Direct 2.6.2 3.0.0 15 behind Apache-2.0
pypdfium2
pypi
Direct 4.30.0 5.9.0 15 behind (Apache-2.0 AND BSD-3-Clause AND LicenseRef-PdfiumThirdParty) OR (Apache-2.0 AND LicenseRef-PdfiumThirdParty) OR (BSD-3-Clause AND LicenseRef-PdfiumThirdParty)
langgraph-prebuilt
pypi
Direct 1.0.2 1.1.0 14 behind Unknown
llama-index
pypi
Direct 0.14.6 0.14.22 14 behind Unknown
pipmaster
pypi
Direct 1.0.9 1.1.13 13 behind Apache-2.0
tifffile
pypi
Direct 2025.10.16 2026.6.1 13 behind BSD-3-Clause
pydantic
pypi
Direct 2.12.3 2.13.4 12 behind MIT
starlette
pypi
Direct 0.49.1 1.2.1 12 behind BSD-3-Clause
wcwidth
pypi
Direct 0.2.14 0.7.0 12 behind MIT
datasets
pypi
Direct 4.4.1 4.8.5 11 behind Apache-2.0
gunicorn
pypi
Direct 23.0.0 26.0.0 11 behind MIT
opensearch-protobufs
pypi
Direct 0.19.0 1.5.0 11 behind Unknown
pandas
pypi
Direct 2.2.3 3.0.3 11 behind BSD-2-Clause AND BSD-3-Clause
platformdirs
pypi
Direct 4.5.0 4.10.0 11 behind MIT
uvicorn
pypi
Direct 0.38.0 0.49.0 11 behind BSD-3-Clause
hf-xet
pypi
Direct 1.2.0 1.5.1.dev1 10 behind Apache-2.0
nvidia-nccl-cu12
pypi
Direct 2.27.5 2.30.4 10 behind Unknown
pydantic-core
pypi
Direct 2.41.4 2.47.0 10 behind Unknown
redis
pypi
Direct 7.0.1 8.0.0 9 behind MIT
rich
pypi
Direct 13.9.4 15.0.0 9 behind MIT
scipy
pypi
Direct 1.15.3 1.17.1 9 behind BSD-3-Clause
omegaconf
pypi
Direct 2.3.0 2.4.0.dev11 8 behind BSD-2-Clause AND BSD-3-Clause
regex
pypi
Direct 2025.10.23 2026.5.9 8 behind CNRI-Python AND Apache-2.0
sqlalchemy
pypi
Direct 2.0.44 2.0.50 8 behind MIT
antlr4-python3-runtime
pypi
Direct 4.9.3 4.13.2 7 behind BSD-3-Clause
greenlet
pypi
Direct 3.2.4 3.5.1 7 behind MIT AND PSF-2.0 AND Python-2.0
grpcio
pypi
Direct 1.76.0 1.81.0 7 behind Apache-2.0 AND BSD-3-Clause AND MPL-2.0
grpcio-tools
pypi
Direct 1.76.0 1.81.0 7 behind Apache-2.0
instructor
pypi
Direct 1.13.0 1.15.1 7 behind MIT
langchain-classic
pypi
Direct 1.0.0 1.0.7 7 behind MIT
opentelemetry-api
pypi
Direct 1.38.0 1.42.1 7 behind Apache-2.0
opentelemetry-exporter-otlp-proto-common
pypi
Direct 1.38.0 1.42.1 7 behind Apache-2.0
opentelemetry-exporter-otlp-proto-http
pypi
Direct 1.38.0 1.42.1 7 behind Apache-2.0
opentelemetry-proto
pypi
Direct 1.38.0 1.42.1 7 behind Apache-2.0
opentelemetry-sdk
pypi
Direct 1.38.0 1.42.1 7 behind Apache-2.0
rapidocr
pypi
Direct 3.4.2 3.8.1 7 behind Unknown
setuptools
pypi
Direct 80.9.0 82.0.1 7 behind MIT
docling-ibm-models
pypi
Direct 3.10.2 3.13.2 6 behind Unknown
fsspec
pypi
Direct 2025.9.0 2026.4.0 6 behind BSD-3-Clause
google-api-core
pypi
Direct 2.28.1 2.31.0 6 behind Apache-2.0
qdrant-client
pypi
Direct 1.15.1 1.18.0 6 behind Apache-2.0
s3transfer
pypi
Direct 0.14.0 0.18.0 6 behind Apache-2.0
striprtf
pypi
Direct 0.0.26 0.0.32 6 behind BSD-2-Clause AND BSD-3-Clause
certifi
pypi
Direct 2025.10.5 2026.5.20 5 behind MPL-2.0
click
pypi
Direct 8.3.0 8.4.1 5 behind BSD-3-Clause
networkx
pypi
Direct 3.4.2 3.6.1 5 behind BSD-2-Clause AND BSD-3-Clause
nvidia-nvshmem-cu12
pypi
Direct 3.3.20 3.6.5 5 behind Unknown
polyfactory
pypi
Direct 2.22.4 3.3.0 5 behind MIT
pydantic-settings
pypi
Direct 2.11.0 2.14.1 5 behind MIT
pymongo
pypi
Direct 4.15.3 4.17.0 5 behind Apache-2.0
pytest-asyncio
pypi
Direct 1.2.0 1.4.0 5 behind Apache-2.0
safetensors
pypi
Direct 0.6.2 0.8.0.dev0 5 behind Apache-2.0
tokenizers
pypi
Direct 0.22.1 0.23.1 5 behind Apache-2.0
voyageai
pypi
Direct 0.3.2 0.3.7 5 behind Unknown
googleapis-common-protos
pypi
Direct 1.72.0 1.75.0 4 behind Apache-2.0
griffe
pypi
Direct 1.14.0 2.0.2 4 behind ISC
identify
pypi
Direct 2.6.15 2.6.19 4 behind MIT
jiter
pypi
Direct 0.11.1 0.15.0 4 behind MIT
llama-index-cli
pypi
Direct 0.5.3 0.5.7 4 behind MIT
neo4j
pypi
Direct 6.0.2 6.2.0 4 behind Apache-2.0
nvidia-cublas-cu12
pypi
Direct 12.8.4.1 12.9.2.10 4 behind Unknown
portalocker
pypi
Direct 2.10.1 3.2.0 4 behind BSD-2-Clause AND BSD-3-Clause
proto-plus
pypi
Direct 1.26.1 1.28.0 4 behind Apache-2.0
psutil
pypi
Direct 7.1.2 7.2.2 4 behind BSD-3-Clause
scipy
pypi
Direct 1.16.3 1.17.1 4 behind BSD-3-Clause
tree-sitter
pypi
Direct 0.23.2 0.25.2 4 behind MIT
anyio
pypi
Direct 4.11.0 4.13.0 3 behind MIT
charset-normalizer
pypi
Direct 3.4.4 3.4.7 3 behind MIT
google-auth
pypi
Direct 2.43.0 3.0.0.dev0 3 behind Apache-2.0
httpx
pypi
Direct 0.28.1 1.0.0.dev3 3 behind BSD-3-Clause
importlib-metadata
pypi
Direct 8.7.0 9.0.0 3 behind Apache-2.0
langchain-community
pypi
Direct 0.3.31 0.4.2 3 behind MIT
langchain-text-splitters
pypi
Direct 1.0.0 1.1.2 3 behind MIT
latex2mathml
pypi
Direct 3.78.1 3.81.0 3 behind MIT
llama-index-indices-managed-llama-cloud
pypi
Direct 0.9.4 0.11.1 3 behind MIT
llama-index-readers-file
pypi
Direct 0.5.4 0.6.0 3 behind MIT
opencv-python
pypi
Direct 4.11.0.86 4.13.0.92 3 behind Apache-2.0 AND MIT
opencv-python-headless
pypi
Direct 4.11.0.86 4.13.0.92 3 behind Apache-2.0 AND MIT
pre-commit
pypi
Direct 4.4.0 4.6.0 3 behind MIT
pyarrow
pypi
Direct 22.0.0 24.0.0 3 behind Apache-2.0
rpds-py
pypi
Direct 0.28.0 2026.5.1 3 behind MIT
scikit-image
pypi
Direct 0.25.2 0.26.0 3 behind BSD-2-Clause AND BSD-3-Clause AND MIT
torchvision
pypi
Direct 0.24.1 0.27.0 3 behind Unknown
accelerate
pypi
Direct 1.11.0 1.13.0 2 behind Apache-2.0
aiosqlite
pypi
Direct 0.21.0 0.22.1 2 behind LicenseRef-scancode-free-unknown AND MIT
deprecated
pypi
Direct 1.2.18 1.3.1 2 behind MIT
jsonpointer
pypi
Direct 3.0.0 3.1.1 2 behind BSD-3-Clause
llama-index-embeddings-openai
pypi
Direct 0.5.1 0.6.0 2 behind MIT
llama-index-instrumentation
pypi
Direct 0.4.2 0.5.0 2 behind MIT
llama-index-readers-llama-parse
pypi
Direct 0.5.1 0.6.1 2 behind MIT
markdown-it-py
pypi
Direct 4.0.0 4.2.0 2 behind MIT
marko
pypi
Direct 2.2.1 2.2.3 2 behind MIT
nvidia-cuda-cupti-cu12
pypi
Direct 12.8.90 12.9.79 2 behind Unknown
nvidia-cuda-nvrtc-cu12
pypi
Direct 12.8.93 12.9.86 2 behind Unknown
nvidia-cuda-runtime-cu12
pypi
Direct 12.8.90 12.9.79 2 behind Unknown
nvidia-cufft-cu12
pypi
Direct 11.3.3.83 11.4.1.4 2 behind Unknown
nvidia-cufile-cu12
pypi
Direct 1.13.1.3 1.14.1.1 2 behind Unknown
nvidia-cusolver-cu12
pypi
Direct 11.7.3.90 11.7.5.82 2 behind Unknown
nvidia-cusparse-cu12
pypi
Direct 12.5.8.93 12.5.10.65 2 behind Unknown
nvidia-cusparselt-cu12
pypi
Direct 0.7.1 0.8.1 2 behind Unknown
nvidia-nvjitlink-cu12
pypi
Direct 12.8.93 12.9.86 2 behind Unknown
nvidia-nvtx-cu12
pypi
Direct 12.8.90 12.9.79 2 behind Unknown
ollama
pypi
Direct 0.6.0 0.6.2 2 behind MIT
ormsgpack
pypi
Direct 1.12.0 1.12.2 2 behind Apache-2.0 AND MIT
python-bidi
pypi
Direct 0.6.7 0.6.10 2 behind Unknown
scikit-network
pypi
Direct 0.33.3 0.33.5 2 behind Unknown
smmap
pypi
Direct 5.0.2 6.0.0 2 behind BSD-3-Clause
tenacity
pypi
Direct 9.1.2 9.1.4 2 behind Apache-2.0
tomli
pypi
Direct 2.3.0 2.4.1 2 behind MIT
tqdm
pypi
Direct 4.67.1 4.67.3 2 behind MPL-2.0
tree-sitter-c
pypi
Direct 0.23.6 0.24.2 2 behind MIT
triton
pypi
Direct 3.5.1 3.7.0 2 behind Unknown
voyageai
pypi
Direct 0.3.5 0.3.7 2 behind MIT
yarl
pypi
Direct 1.22.0 1.24.2 2 behind Apache-2.0
zipp
pypi
Direct 3.23.0 4.1.0 2 behind MIT
zstandard
pypi
Direct 0.23.0 0.25.0 2 behind BSD-3-Clause
aioboto3
pypi
Direct 15.4.0 15.5.0 1 behind Apache-2.0
aiohappyeyeballs
pypi
Direct 2.6.1 2.6.2 1 behind 0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0
aioitertools
pypi
Direct 0.12.0 0.13.0 1 behind MIT
annotated-doc
pypi
Direct 0.0.3 0.0.4 1 behind MIT
attrs
pypi
Direct 25.4.0 26.1.0 1 behind MIT
beautifulsoup4
pypi
Direct 4.14.2 4.14.3 1 behind MIT
cfgv
pypi
Direct 3.4.0 3.5.0 1 behind MIT
dill
pypi
Direct 0.4.0 0.4.1 1 behind BSD-3-Clause
distlib
pypi
Direct 0.4.0 0.4.1 1 behind PSF-2.0 AND Python-2.0
docstring-parser
pypi
Direct 0.17.0 0.18.0 1 behind MIT
exceptiongroup
pypi
Direct 1.3.0 1.3.1 1 behind MIT AND Python-2.0
imageio
pypi
Direct 2.37.2 2.37.3 1 behind BSD-2-Clause
jmespath
pypi
Direct 1.0.1 1.1.0 1 behind MIT
joblib
pypi
Direct 1.5.2 1.5.3 1 behind BSD-3-Clause
jsonschema
pypi
Direct 4.25.1 4.26.0 1 behind MIT
langchain-community
pypi
Direct 0.4.1 0.4.2 1 behind MIT
multidict
pypi
Direct 6.7.0 6.7.1 1 behind Apache-2.0
multiprocess
pypi
Direct 0.70.18 0.70.19 1 behind BSD-3-Clause
nodeenv
pypi
Direct 1.9.1 1.10.0 1 behind BSD-2-Clause AND BSD-3-Clause
nvidia-curand-cu12
pypi
Direct 10.3.9.90 10.3.10.19 1 behind Unknown
opensearch-py
pypi
Direct 3.1.0 3.2.0 1 behind Apache-2.0
propcache
pypi
Direct 0.4.1 0.5.2 1 behind Apache-2.0
pyclipper
pypi
Direct 1.3.0.post6 1.4.0 1 behind BSL-1.0 AND MIT
tabulate
pypi
Direct 0.9.0 0.10.0 1 behind MIT
tiktoken
pypi
Direct 0.12.0 0.13.0 1 behind MIT
tree-sitter-javascript
pypi
Direct 0.23.1 0.25.0 1 behind MIT
tree-sitter-python
pypi
Direct 0.23.6 0.25.0 1 behind MIT
websockets
pypi
Direct 15.0.1 16.0.0 1 behind BSD-3-Clause
xxhash
pypi
Direct 3.6.0 3.7.0 1 behind BSD-2-Clause AND BSD-3-Clause

License Breakdown

Unknown 173
MIT 119
Apache-2.0 53
BSD-3-Clause 27
BSD-2-Clause AND BSD-3-Clause 14
Apache-2.0 AND MIT 6
BSD-2-Clause 6
BSD-2-Clause AND BSD-3-Clause AND MIT 2
ISC 2
MPL-2.0 2
PSF-2.0 2
(Apache-2.0 AND BSD-3-Clause AND LicenseRef-PdfiumThirdParty) OR (Apache-2.0 AND LicenseRef-PdfiumThirdParty) OR (BSD-3-Clause AND LicenseRef-PdfiumThirdParty) 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 1
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND MIT AND MPL-2.0 1
BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain AND Unlicense 1
BSD-3-Clause AND GPL-1.0-or-later 1
BSD-3-Clause AND LGPL-2.1-only 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
BSD-3-Clause AND MIT 1
BSD-3-Clause AND TCL 1
BSD-3-Clause OR Apache-2.0 1
BSL-1.0 AND MIT 1
CNRI-Python AND Apache-2.0 1
ISC AND MPL-2.0 1
LicenseRef-scancode-free-unknown AND MIT 1
LicenseRef-scancode-public-domain AND MIT 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
MIT AND AFL-3.0 1
MIT AND PSF-2.0 AND Python-2.0 1
MIT AND Python-2.0 1
MIT AND ZPL-2.1 1
MIT-0 1
PSF-2.0 AND Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Unlicense 1

CVE Severity

critical 2
high 15
medium 12
low 3
unknown 0

Beta — feedback welcome: [email protected]