Skip to content
Tools / openchangelog / Dependencies

Dependency Analysis

openchangelog

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

44% Freshness
1050 Dependencies
438 Outdated
0 Stale
22.0 Avg Behind

Dependency List

Latest release v0.7.2

Dependency Type Current Latest Behind CVE License
next
npm
Direct 14.2.15 14 critical MIT
next
npm
Direct 15.0.0 2 critical MIT
minimatch
npm
Transitive 9.0.5 10.2.5 36 behind 3 high ISC
minimatch
npm
Transitive 9.0.5 10.2.5 36 behind 3 high ISC
glob
npm
Transitive 10.3.10 13.0.6 26 behind 1 high CC-BY-SA-4.0 AND ISC
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
flatted
npm
Transitive 3.3.1 3.4.2 6 behind 2 high ISC
flatted
npm
Transitive 3.3.1 3.4.2 6 behind 2 high ISC
cross-spawn
npm
Transitive 7.0.3 7.0.6 3 behind 1 high MIT
cross-spawn
npm
Transitive 7.0.3 7.0.6 3 behind 1 high MIT
cross-spawn
npm
Transitive 7.0.3 7.0.6 3 behind 1 high MIT
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
braces
npm
Transitive 3.0.2 3.0.3 1 behind 1 high MIT
rollup
npm
Transitive 4.24.0 1 high MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
@babel/runtime
npm
Transitive 7.25.0 7.29.7 36 behind 1 medium MIT
postcss
npm
Transitive 8.4.31 8.5.15 34 behind 1 medium MIT
postcss
npm
Transitive 8.4.31 8.5.15 34 behind 1 medium MIT
esbuild
npm
Transitive 0.23.1 0.28.0 25 behind 1 medium MIT
nanoid
npm
Transitive 3.3.7 5.1.11 24 behind 1 medium MIT
nanoid
npm
Transitive 3.3.7 5.1.11 24 behind 1 medium MIT
nanoid
npm
Transitive 3.3.7 5.1.11 24 behind 1 medium MIT
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
yaml
npm
Transitive 2.6.0 2.9.0 12 behind 1 medium ISC
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
micromatch
npm
Transitive 4.0.5 4.0.8 3 behind 1 medium MIT
golang.org/x/net
golang
Direct 0.25.0 5 medium BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
tsup
npm
Direct 8.3.0 1 low MIT
golang.org/x/net
golang
Transitive v0.47.0 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang

License Breakdown

MIT 795
ISC 75
Apache-2.0 57
BSD-3-Clause 24
BSD-2-Clause 20
Unknown 16
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 10
LGPL-3.0-or-later 8
BlueOak-1.0.0 7
MPL-2.0 5
Apache-2.0 AND BSD-2-Clause 4
CC0-1.0 AND MIT 4
0BSD 3
Apache-2.0 AND MIT 3
AGPL-3.0 AND AGPL-3.0-only 2
Apache-2.0 AND LGPL-3.0-or-later 2
BSD-2-Clause AND BSD-2-Clause-Views 2
CC-BY-4.0 2
CC-BY-SA-4.0 AND ISC 2
CC0-1.0 2
ISC AND MIT 2
Python-2.0 2
Apache-2.0 AND BSD-3-Clause 1
Apache-2.0 AND LGPL-3.0-or-later AND MIT 1

CVE Severity

critical 2
high 14
medium 16
low 1
unknown 1

Beta — feedback welcome: [email protected]