Skip to content
Tools / mcp-toolbox / Dependencies

Dependency Analysis

mcp-toolbox

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

57% Freshness
2505 Dependencies
855 Outdated
0 Stale
9.3 Avg Behind

Dependency List

Latest release v1.1.0

Dependency Type Current Latest Behind CVE License
google.golang.org/grpc
golang
Transitive v1.78.0 1 critical Apache-2.0
google.golang.org/grpc
golang
Transitive v1.78.0 1 critical Apache-2.0
google.golang.org/grpc
golang
Transitive v1.78.0 1 critical Apache-2.0
@mikro-orm/knex
npm
Transitive 6.6.8 6.6.14 36 behind 1 high MIT
@mikro-orm/knex
npm
Transitive 6.6.8 6.6.14 36 behind 1 high MIT
tar
npm
Transitive 6.2.1 7.5.16 27 behind 6 high ISC
tar
npm
Transitive 6.2.1 7.5.16 27 behind 6 high ISC
axios
npm
Transitive 1.15.0 1.17.0 8 behind 13 high MIT
axios
npm
Transitive 1.15.0 1.17.0 8 behind 13 high MIT
axios
npm
Transitive 1.15.0 1.17.0 8 behind 13 high MIT
axios
npm
Transitive 1.15.0 1.17.0 8 behind 13 high MIT
axios
npm
Transitive 1.15.0 1.17.0 8 behind 13 high MIT
axios
npm
Transitive 1.15.0 1.17.0 8 behind 13 high MIT
fast-xml-builder
npm
Transitive 1.1.4 1.2.0 6 behind 1 high MIT
fast-xml-builder
npm
Transitive 1.1.4 1.2.0 6 behind 1 high MIT
path-to-regexp
npm
Transitive 8.3.0 8.4.2 4 behind 2 high MIT
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
go.opentelemetry.io/otel
golang
Transitive v1.40.0 1 high Apache-2.0 AND BSD-3-Clause
go.opentelemetry.io/otel/sdk
golang
Transitive v1.40.0 1 high Apache-2.0 AND BSD-3-Clause
fast-xml-parser
npm
Transitive 5.5.7 5.8.0 13 behind 1 medium MIT
yaml
npm
Transitive 2.7.0 2.9.0 10 behind 1 medium ISC
hono
npm
Transitive 4.12.14 4.12.23 9 behind 2 medium MIT
hono
npm
Transitive 4.12.14 4.12.23 9 behind 2 medium MIT
fast-xml-builder
npm
Transitive 1.1.5 1.2.0 5 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
ip-address
npm
Transitive 10.1.0 10.2.0 2 behind 1 medium MIT
ip-address
npm
Transitive 10.1.0 10.2.0 2 behind 1 medium MIT
@tootallnate/once
npm
Transitive 1.1.2 3.0.1 3 behind 1 low MIT
@tootallnate/once
npm
Transitive 1.1.2 3.0.1 3 behind 1 low MIT
golang.org/x/net
golang
Transitive v0.49.0 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/net
golang
Transitive v0.49.0 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/net
golang
Transitive v0.49.0 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/net
golang
Transitive v0.49.0 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/net
golang
Transitive v0.49.0 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/net
golang
Transitive v0.49.0 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang

License Breakdown

MIT 1482
Apache-2.0 457
ISC 160
BSD-3-Clause 120
Unknown 99
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 46
Apache-2.0 AND BSD-3-Clause 39
BSD-2-Clause 24
CC0-1.0 AND MIT 21
BlueOak-1.0.0 13
Apache-2.0 AND MIT 5
0BSD 4
Apache-2.0 OR (Apache-2.0 AND LGPL-3.0-only) 3
BSD-2-Clause AND BSD-3-Clause 3
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 2
BSD-2-Clause AND JSON 2
ISC AND MIT 2
LGPL-2.1-or-later 2
LicenseRef-scancode-generic-cla AND MIT 2
MIT AND MIT-0 2
MIT OR (MIT AND WTFPL) 2
MPL-2.0 2
AFL-2.1 AND AFL-3.0 AND BSD-3-Clause 1
Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause 1
Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND BSL-1.0 AND CC-BY-3.0 AND HPND AND MIT AND NCSA AND OpenSSL AND Zlib 1
Apache-2.0 AND BSD-3-Clause AND MIT 1
Apache-2.0 AND CC-BY-SA-4.0 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 1
Apache-2.0 AND Unlicense 1
BSD-3-Clause OR GPL-2.0-only 1
CC-BY-4.0 1
GPL-3.0 AND GPL-3.0-only 1
LicenseRef-scancode-public-domain 1
MIT-0 1

CVE Severity

critical 3
high 19
medium 14
low 2
unknown 6

Beta — feedback welcome: [email protected]