Skip to content
Tools / mlflow / Dependencies

Dependency Analysis

mlflow

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

43% Freshness
6495 Dependencies
2972 Outdated
0 Stale
35.5 Avg Behind

Dependency List

Latest release v3.12.0

Dependency Type Current Latest Behind CVE License
mlflow
pypi
Direct 2.7.1 3.13.0 100 behind 2 critical Unknown
mlflow
pypi
Direct 2.8.1 3.13.0 98 behind 25 critical Apache-2.0
plotly.js
npm
Direct 2.5.1 3.6.0 88 behind 1 critical MIT
mlflow
pypi
Direct 2.12.2 3.13.0 85 behind 30 critical Apache-2.0
fast-xml-parser
npm
Direct 5.2.5 5.8.0 35 behind 7 critical MIT
pyarrow
pypi
Direct 8.0.0 24.0.0 26 behind 2 critical Apache-2.0
protobufjs
npm
Transitive 7.5.4 8.5.0 20 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
fsevents
npm
Transitive 1.2.9 2.3.3 16 behind 2 critical MIT
basic-ftp
npm
Transitive 5.0.5 6.0.1 8 behind 4 critical Apache-2.0 AND MIT
pbkdf2
npm
Transitive 3.0.17 3.1.6 7 behind 2 critical MIT
cipher-base
npm
Transitive 1.0.4 1.0.7 3 behind 1 critical MIT
@remix-run/router
npm
Transitive 1.0.1 1.23.3 220 behind 1 high MIT
undici
npm
Transitive 5.10.0 8.3.0 159 behind 13 high MIT
protobuf
pypi
Direct 4.24.0 7.35.0 76 behind 2 high BSD-3-Clause
tar
npm
Transitive 4.4.10 7.5.16 73 behind 12 high ISC
immutable
npm
Transitive 3.7.6 5.1.6 52 behind 1 high BSD-3-Clause AND LicenseRef-scancode-facebook-patent-rights-2
semver
npm
Transitive 5.3.0 7.8.1 51 behind 1 high ISC
cryptography
pypi
Direct 39.0.1 48.0.0 46 behind 10 high Apache-2.0 AND BSD-3-Clause AND PSF-2.0 AND Python-2.0
webpack-dev-middleware
npm
Transitive 3.7.3 8.0.3 38 behind 1 high MIT
sanitize-html
npm
Direct 1.27.5 2.17.4 37 behind 5 high MIT
minimatch
npm
Transitive 9.0.5 10.2.5 36 behind 3 high ISC
minimatch
npm
Transitive 9.0.5 10.2.5 36 behind 3 high ISC
minimatch
npm
Transitive 9.0.5 10.2.5 36 behind 3 high ISC
http-proxy-middleware
npm
Direct 1.3.1 4.0.0 29 behind 3 high MIT
ws
npm
Transitive 8.14.1 8.21.0 20 behind 1 high MIT
starlette
pypi
Direct 0.46.2 1.2.1 19 behind 2 high BSD-2-Clause AND BSD-3-Clause
svgo
npm
Transitive 2.8.0 4.0.1 19 behind 1 high MIT
ssri
npm
Transitive 8.0.0 14.0.0 17 behind 1 high ISC
glob
npm
Transitive 10.4.5 13.0.6 13 behind 1 high ISC
serialize-javascript
npm
Transitive 4.0.0 7.0.5 11 behind 2 high BSD-3-Clause
ansi-regex
npm
Transitive 4.1.0 6.2.2 9 behind 1 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
trim-newlines
npm
Transitive 1.0.0 5.0.0 9 behind 1 high MIT
@babel/plugin-transform-modules-systemjs
npm
Transitive 7.29.0 7.29.7 8 behind 1 high MIT
@babel/plugin-transform-modules-systemjs
npm
Transitive 7.29.0 7.29.7 8 behind 1 high MIT
cross-spawn
npm
Transitive 6.0.5 7.0.6 7 behind 1 high MIT
vega-interpreter
npm
Transitive 1.0.4 2.2.1 7 behind 1 high BSD-3-Clause
nth-check
npm
Transitive 1.0.2 3.0.1 6 behind 1 high BSD-2-Clause AND BSD-3-Clause
d3-color
npm
Transitive 1.4.1 3.1.0 5 behind 1 high BSD-3-Clause
path-to-regexp
npm
Transitive 0.1.12 8.4.2 5 behind 1 high MIT
prismjs
npm
Transitive 1.25.0 1.30.0 5 behind 2 high MIT
validator
npm
Transitive 13.15.15 13.15.35 5 behind 2 high MIT
@xmldom/xmldom
npm
Transitive 0.8.11 0.9.10 4 behind 5 high MIT
braces
npm
Transitive 2.3.2 3.0.3 4 behind 1 high MIT
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 1 high ISC
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 1 high ISC
gitpython
pypi
Direct 3.1.46 3.1.50 4 behind 1 high BSD-3-Clause
lodash-es
npm
Transitive 4.17.21 4.18.1 4 behind 3 high CC0-1.0 AND MIT
python-multipart
pypi
Direct 0.0.26 0.0.30 4 behind 1 high Unknown
trim
npm
Transitive 0.0.1 1.0.1 4 behind 1 high MIT
gitpython
pypi
Direct 3.1.47 3.1.50 3 behind 2 high Unknown
pyopenssl
pypi
Direct 25.3.0 26.2.0 3 behind 2 high Apache-2.0
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
jws
npm
Transitive 4.0.0 4.0.1 2 behind 1 high MIT
lodash
npm
Direct 4.17.23 4.18.1 2 behind 2 high CC0-1.0 AND MIT
underscore
npm
Transitive 1.13.6 1.13.8 2 behind 1 high MIT
flatted
npm
Transitive 3.4.1 3.4.2 1 behind 1 high Artistic-2.0 AND ISC
mako
pypi
Direct 1.3.11 1.3.12 1 behind 1 high MIT
mistune
pypi
Direct 3.2.0 3.2.1 1 behind 1 high BSD-3-Clause
node-forge
npm
Transitive 1.3.3 1.4.0 1 behind 4 high BSD-3-Clause OR GPL-2.0-only
pyasn1
pypi
Direct 0.6.2 0.6.3 1 behind 1 high BSD-2-Clause AND BSD-3-Clause AND MIT
ip
npm
Transitive 2.0.1 2.0.1 Current 1 high MIT
org.apache.spark:spark-core_2.12
maven
Direct 3.5.0 1 high Apache-2.0
org.apache.spark:spark-core_2.13
maven
Direct 3.5.0 1 high Apache-2.0
org.eclipse.jetty:jetty-server
maven
Direct 9.4.11.v20180605 12 high Apache-2.0
org.testng:testng
maven
Direct 6.14.3 1 high Apache-2.0
tornado
pypi
Direct 6.1 6.5.6 9 high Apache-2.0
react-router
npm
Direct 6.4.1 7.16.0 958 behind 1 medium MIT
langchain
pypi
Direct 0.1.20 1.3.4 110 behind 2 medium MIT
postcss
npm
Transitive 7.0.39 8.5.15 69 behind 2 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
yaml
npm
Transitive 1.10.2 2.9.0 49 behind 1 medium ISC
qs
npm
Direct 6.10.5 6.15.2 43 behind 2 medium BSD-3-Clause
scikit-learn
pypi
Direct 1.0.2 1.9.0 31 behind 1 medium BSD-3-Clause
brace-expansion
npm
Transitive 2.0.1 5.0.6 16 behind 2 medium MIT
dompurify
npm
Transitive 3.2.6 3.4.8 15 behind 3 medium Apache-2.0 OR MPL-2.0
mermaid
npm
Transitive 11.9.0 11.15.0 12 behind 2 medium MIT
dompurify
npm
Direct 2.5.9 3.4.8 11 behind 7 medium (MPL-2.0 OR Apache-2.0)
micromatch
npm
Transitive 3.1.10 4.0.8 9 behind 1 medium MIT
jinja2
pypi
Direct 3.0.3 3.1.6 7 behind 5 medium BSD-2-Clause AND BSD-3-Clause
showdown
npm
Direct 1.9.1 2.1.0 7 behind 1 medium BSD-3-Clause
ip-address
npm
Transitive 9.0.5 10.2.0 6 behind 1 medium MIT
webpack-dev-server
npm
Transitive 4.15.2 5.2.4 6 behind 2 medium MIT
bn.js
npm
Transitive 4.12.0 5.2.3 5 behind 1 medium MIT
js-yaml
npm
Direct 3.14.1 4.2.0 5 behind 1 medium MIT
js-yaml
npm
Transitive 3.14.1 4.2.0 5 behind 1 medium MIT
js-yaml
npm
Transitive 3.14.1 4.2.0 5 behind 1 medium MIT
cryptography
pypi
Direct 46.0.5 48.0.0 4 behind 1 medium Apache-2.0 AND BSD-3-Clause
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 1 medium CC0-1.0 AND MIT
pip
pypi
Direct 26.0.1 26.1.2 3 behind 2 medium MIT
protocol-buffers-schema
npm
Transitive 3.5.1 3.6.1 3 behind 1 medium MIT
mako
pypi
Direct 1.3.10 1.3.12 2 behind 1 medium MIT
markdown-it
npm
Transitive 14.1.0 14.2.0 2 behind 1 medium MIT
follow-redirects
npm
Transitive 1.15.11 1.16.0 1 behind 1 medium MIT
follow-redirects
npm
Transitive 1.15.11 1.16.0 1 behind 1 medium MIT
mdast-util-to-hast
npm
Transitive 13.2.0 13.2.1 1 behind 1 medium MIT
mdast-util-to-hast
npm
Transitive 13.2.0 13.2.1 1 behind 1 medium MIT
uuid
npm
Direct 13.0.0 14.0.0 1 behind 1 medium MIT
diskcache
pypi
Direct 5.6.3 5.6.3 Current 1 medium Apache-2.0
junit:junit
maven
Direct 4.12 1 medium EPL-1.0
org.apache.httpcomponents:httpclient
maven
Direct 4.5.6 1 medium Apache-2.0
webpack
npm
Transitive 5.101.0 5.107.2 19 behind 2 low MIT
diff
npm
Transitive 4.0.2 9.0.0 18 behind 1 low BSD-3-Clause
es5-ext
npm
Transitive 0.10.50 0.10.64 14 behind 1 low ISC
cookie
npm
Direct 0.3.1 1.1.1 13 behind 1 low MIT
tmp
npm
Transitive 0.0.33 0.2.7 9 behind 1 low MIT
ip
npm
Transitive 1.1.5 2.0.1 6 behind 1 low MIT
@tootallnate/once
npm
Transitive 1.1.2 3.0.1 3 behind 1 low MIT
min-document
npm
Transitive 2.19.0 2.19.2 2 behind 1 low MIT
elliptic
npm
Transitive 6.6.1 6.6.1 Current 1 low MIT

License Breakdown

MIT 4798
Unknown 395
ISC 331
Apache-2.0 269
BSD-3-Clause 204
BSD-2-Clause 117
MIT-0 63
CC0-1.0 48
Apache-2.0 AND MIT 44
BSD-2-Clause AND BSD-3-Clause 31
MPL-2.0 15
CC0-1.0 AND MIT 13
ISC AND MIT 12
BlueOak-1.0.0 10
0BSD 9
Apache-2.0 AND BSD-2-Clause 8
BSD-3-Clause AND MIT 7
LicenseRef-scancode-generic-cla AND MIT 6
Python-2.0 5
Zlib 5
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 4
CC-BY-4.0 4
MIT OR (CC0-1.0 AND MIT) 4
Unlicense 4
CC0-1.0 OR MIT OR (CC0-1.0 AND MIT) 3
LicenseRef-scancode-public-domain AND Unlicense 3
LicenseRef-scancode-unicode AND MIT 3
Apache-2.0 AND BSD-3-Clause 2
Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1 2
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 2
BSD-2-Clause AND BSD-2-Clause-Views 2
BSD-2-Clause AND BSD-3-Clause AND MIT 2
BSD-3-Clause AND LicenseRef-scancode-facebook-patent-rights-2 2
BSD-3-Clause AND LicenseRef-scancode-protobuf 2
CC-BY-3.0 2
ISC AND LicenseRef-scancode-unknown-license-reference 2
MIT AND HPND 2
MIT AND Python-2.0 2
PSF-2.0 2
(Apache-2.0 AND BSD-3-Clause AND MIT) OR (Apache-2.0 AND MIT) 1
(MPL-2.0 OR Apache-2.0) 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 1
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 1
Apache-2.0 AND BSD-3-Clause AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND BUSL-1.1 1
Apache-2.0 AND CC-BY-3.0 AND CC-BY-4.0 AND CC-BY-SA-3.0 AND CC0-1.0 AND ISC AND LicenseRef-scancode-unknown-license-reference AND MIT AND MPL-2.0 AND OFL-1.1 1
Apache-2.0 AND GPL-1.0-or-later AND LicenseRef-scancode-other-copyleft AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND ISC 1
Apache-2.0 AND MIT AND MPL-2.0 1
Apache-2.0 OR (Apache-2.0 AND LGPL-3.0-only) 1
Apache-2.0 OR MIT 1
Apache-2.0 OR MPL-1.1 OR (Apache-2.0 AND MPL-1.1) 1
Apache-2.0 OR MPL-2.0 1
Apache-2.0 OR Unlicense OR (Apache-2.0 AND Unlicense) 1
Artistic-2.0 AND ISC 1
Artistic-2.0 AND MIT 1
BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain AND Unlicense 1
BSD-3-Clause AND ISC AND MIT 1
BSD-3-Clause AND LicenseRef-scancode-generic-cla AND MIT 1
BSD-3-Clause OR Apache-2.0 1
BSD-3-Clause OR GPL-2.0-only 1
BSL-1.0 1
CC-BY-3.0 AND CC-BY-SA-3.0 AND MIT 1
CC-BY-SA-4.0 AND ISC 1
CC0-1.0 AND Unlicense 1
CDDL-1.0 OR GPL-2.0-only WITH Classpath-exception-2.0 1
CNRI-Python AND Apache-2.0 1
EPL-1.0 1
ISC AND JSON AND MIT 1
ISC AND MPL-2.0 1
LGPL-2.0-or-later AND LGPL-2.1-only AND LicenseRef-scancode-public-domain AND MIT AND MPL-1.1 1
LGPL-2.0-or-later AND LGPL-3.0-or-later 1
LGPL-2.1-or-later 1
LicenseRef-scancode-commercial-license AND LicenseRef-scancode-other-permissive AND MIT 1
LicenseRef-scancode-free-unknown AND MIT 1
LicenseRef-scancode-public-domain 1
LicenseRef-scancode-public-domain AND MIT 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
MIT AND HPND-Markus-Kuhn 1
MIT AND MIT-0 1
MIT AND MITNFA 1
MIT AND MPL-2.0 1
MIT AND OFL-1.1 1
MIT AND PSF-2.0 1
MIT AND Python-2.0 AND Python-2.0.1 1
MIT AND Unlicense 1
MIT AND WTFPL 1
MIT AND ZPL-2.1 1
MIT AND Zlib 1
MIT OR (Apache-2.0 AND MIT) 1
MIT OR WTFPL OR (MIT AND WTFPL) 1
MIT-CMU 1
MPL-2.0 AND Apache-2.0 1
MPL-2.0 AND Python-2.0 1
PSF-2.0 AND Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
ZPL-2.1 1

CVE Severity

critical 11
high 58
medium 35
low 9
unknown 0

Beta — feedback welcome: [email protected]