Skip to content
Tools / manyfold / Dependencies

Dependency Analysis

manyfold

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

79% Freshness
1004 Dependencies
165 Outdated
0 Stale
45.5 Avg Behind

Dependency List

Latest release v0.139.0

Dependency Type Current Latest Behind CVE License
minimatch
npm
Transitive 9.0.5 10.2.5 36 behind 3 high ISC
tar
npm
Transitive 6.2.1 7.5.16 27 behind 6 high ISC
glob
npm
Transitive 10.4.5 13.0.6 13 behind 1 high ISC
nokogiri
gem
Direct 1.19.2 2 high MIT
brace-expansion
npm
Transitive 5.0.2 5.0.6 9 behind 1 medium MIT
devise
gem
Direct 5.0.3 1 medium CC-BY-NC-4.0 AND CC-BY-NC-ND-4.0 AND MIT
brace-expansion
npm
Transitive 2.0.1 5.0.6 16 behind 1 low MIT

License Breakdown

MIT 720
ISC 59
Unknown 56
Apache-2.0 42
BSD-2-Clause 16
BSD-2-Clause OR Ruby OR (BSD-2-Clause AND Ruby) 12
BSD-2-Clause OR (BSD-2-Clause AND Ruby) 8
BlueOak-1.0.0 6
CC0-1.0 AND MIT 6
(BSD-2-Clause AND MIT AND Ruby) OR (BSD-2-Clause AND MIT) 5
BSD-3-Clause 5
LicenseRef-scancode-unknown-license-reference AND MIT 5
ISC AND MIT 3
MIT AND Ruby 3
0BSD 2
Apache-2.0 AND BSD-2-Clause 2
Apache-2.0 AND MIT 2
BSD-2-Clause OR Ruby 2
LicenseRef-scancode-public-domain AND MIT 2
LicenseRef-scancode-public-domain AND Unlicense 2
Ruby 2
(Apache-2.0 AND BSD-2-Clause AND MIT AND Ruby) OR (BSD-2-Clause AND GPL-2.0-only AND MIT AND Ruby) 1
(Artistic-1.0-Perl AND Artistic-2.0 AND GPL-1.0-or-later AND GPL-2.0-only AND GPL-2.0-or-later AND MIT) OR (Artistic-2.0 AND GPL-1.0-or-later AND GPL-2.0-only AND GPL-2.0-or-later AND MIT) 1
(Artistic-1.0-Perl AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND MIT AND OFL-1.1 AND Ruby) OR (BSD-3-Clause AND GPL-1.0-or-later AND LicenseRef-scancode-unknown-license-reference AND MIT AND OFL-1.1 AND Ruby) 1
(BSD-2-Clause AND BSD-3-Clause AND Ruby) OR (BSD-2-Clause AND BSD-3-Clause) 1
(BSD-2-Clause AND GPL-2.0-only AND MIT AND Ruby) OR (BSD-2-Clause AND MIT AND Ruby) 1
(BSD-2-Clause AND PostgreSQL AND Ruby) OR (BSD-2-Clause AND PostgreSQL) 1
(LGPL-3.0 AND LGPL-3.0-only AND LicenseRef-scancode-unknown-license-reference) OR (LGPL-3.0 AND LicenseRef-scancode-commercial-license AND LicenseRef-scancode-unknown-license-reference) 1
0BSD AND MIT 1
Apache-2.0 AND BSD-3-Clause 1
Apache-2.0 AND BSD-3-Clause AND MIT 1
Apache-2.0 AND GPL-2.0-only 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-2-Clause AND GPL-2.0-or-later AND MIT 1
BSD-2-Clause AND MIT 1
BSD-2-Clause OR BSD-3-Clause OR MPL-2.0 1
BSD-3-Clause AND LicenseRef-scancode-public-domain 1
BSD-3-Clause AND MIT 1
BSD-3-Clause AND Ruby 1
CC-BY-3.0 AND ISC AND MIT 1
CC-BY-3.0 AND MIT 1
CC-BY-4.0 1
CC-BY-NC-4.0 AND CC-BY-NC-ND-4.0 AND MIT 1
CC-BY-NC-SA-4.0 AND MIT 1
GPL-2.0 AND GPL-2.0-only AND GPL-2.0-or-later AND Ruby 1
Hippocratic-2.1 OR MIT 1
ISC AND LicenseRef-scancode-sudo 1
JSON AND LicenseRef-scancode-unknown-license-reference AND MIT 1
LGPL-2.1-only AND LGPL-2.1-or-later AND MIT 1
LicenseRef-scancode-dco-1.1 AND MIT 1
LicenseRef-scancode-proprietary-license 1
LicenseRef-scancode-proprietary-license AND MIT 1
LicenseRef-scancode-unicode AND Unicode-DFS-2016 1
LicenseRef-scancode-warranty-disclaimer AND MIT 1
MIT AND MIT-0 1
MIT AND MPL-2.0 1
MIT OR (CC0-1.0 AND MIT) 1
MPL-2.0 1
Python-2.0 1
Ruby OR BSD-2-Clause 1
Ruby OR GPL-2.0-only 1
Ruby OR LGPL-3.0+ 1
Unlicense 1
WTFPL 1

CVE Severity

critical 0
high 4
medium 2
low 1
unknown 0

Beta — feedback welcome: [email protected]