Skip to content
Tools / OpenSign / Dependencies

Dependency Analysis

OpenSign

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

59% Freshness
2223 Dependencies
707 Outdated
0 Stale
8.5 Avg Behind

Dependency List

Latest release v2.38.0

Dependency Type Current Latest Behind CVE License
protobufjs
npm
Transitive 7.5.4 8.5.0 20 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
protobufjs
npm
Transitive 7.5.4 8.5.0 20 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
parse-server
npm
Direct 8.6.40 33 critical Apache-2.0
vite
npm
Direct 7.3.1 8.0.16 33 behind 3 high BSD-2-Clause AND CC0-1.0 AND ISC AND MIT
tar
npm
Transitive 6.2.1 7.5.16 27 behind 6 high ISC
fast-xml-parser
npm
Transitive 5.4.1 5.8.0 23 behind 3 high MIT
undici
npm
Transitive 7.22.0 8.3.0 21 behind 6 high MIT
undici
npm
Transitive 7.22.0 8.3.0 21 behind 6 high MIT
fast-xml-builder
npm
Transitive 1.0.0 1.2.0 11 behind 1 high MIT
axios
npm
Direct 1.13.6 1.17.0 10 behind 15 high MIT
axios
npm
Direct 1.13.6 1.17.0 10 behind 15 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
path-to-regexp
npm
Transitive 0.1.12 8.4.2 5 behind 1 high MIT
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 2 high ISC
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 2 high ISC
path-to-regexp
npm
Transitive 8.3.0 8.4.2 4 behind 2 high MIT
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
lodash-es
npm
Transitive 4.17.23 4.18.1 2 behind 2 high MIT
node-forge
npm
Direct 1.3.3 1.4.0 1 behind 4 high BSD-3-Clause OR GPL-2.0-only
@apollo/server
npm
Transitive 4.12.1 2 high MIT
xlsx
npm
Direct 0.20.3 2 high Unknown
brace-expansion
npm
Transitive 1.1.12 5.0.6 10 behind 1 medium MIT
brace-expansion
npm
Transitive 1.1.12 5.0.6 10 behind 1 medium MIT
dompurify
npm
Direct 3.3.3 3.4.8 9 behind 4 medium (Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0)
postcss
npm
Direct 8.5.8 8.5.15 7 behind 1 medium MIT
yaml
npm
Transitive 2.8.1 2.9.0 7 behind 1 medium ISC
i18next-http-backend
npm
Direct 3.0.2 4.0.0 6 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
follow-redirects
npm
Transitive 1.15.11 1.16.0 1 behind 1 medium MIT
follow-redirects
npm
Transitive 1.15.11 1.16.0 1 behind 1 medium MIT
insane
npm
Transitive 2.6.2 1 medium MIT
nodemailer
npm
Direct 8.0.2 2 medium MIT AND MIT-0
@tootallnate/once
npm
Transitive 2.0.0 3.0.1 2 behind 1 low MIT
quill
npm
Transitive 2.0.3 1 low BSD-3-Clause

License Breakdown

MIT 1712
Apache-2.0 215
ISC 122
BSD-3-Clause 54
BSD-2-Clause 33
BSD-2-Clause AND LGPL-2.0-only AND LGPL-2.1-only AND LGPL-3.0-only AND LGPL-3.0-or-later AND LicenseRef-scancode-other-permissive AND MIT AND MPL-2.0 10
BlueOak-1.0.0 9
CC0-1.0 AND MIT 8
Unknown 8
0BSD 5
Apache-2.0 AND BSD-2-Clause AND LGPL-2.0-only AND LGPL-2.1-only AND LGPL-3.0-only AND LGPL-3.0-or-later AND LicenseRef-scancode-other-permissive AND MIT AND MPL-2.0 3
Apache-2.0 AND MIT 3
BSD-2-Clause AND BSD-2-Clause-Views 2
BSD-3-Clause AND LicenseRef-scancode-protobuf 2
BSD-3-Clause AND MIT 2
CC-BY-4.0 2
ISC AND MIT 2
LicenseRef-scancode-unicode AND MIT 2
MIT AND Zlib 2
MIT-0 2
Python-2.0 2
(Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0) 1
(BSD-3-Clause AND GPL-1.0-or-later AND GPL-2.0 AND GPL-2.0-only) OR (BSD-3-Clause AND GPL-1.0-or-later AND GPL-2.0-only) 1
0BSD AND ISC AND MIT 1
0BSD AND MIT 1
AGPL-3.0-or-later 1
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 OR (Apache-2.0 AND LGPL-3.0-only) 1
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 1
BSD-3-Clause OR GPL-2.0-only 1
CC-BY-3.0 AND CC-BY-SA-3.0 AND MIT 1
CC0-1.0 1
CC0-1.0 OR MIT OR (CC0-1.0 AND MIT) 1
GPL-3.0-only OR MIT 1
LicenseRef-scancode-generic-cla AND MIT 1
MIT AND MIT-0 1
MIT AND MITNFA 1
MIT AND WTFPL 1
MIT OR (CC0-1.0 AND MIT) 1
MIT OR LicenseRef-scancode-public-domain 1
MPL-2.0 1

CVE Severity

critical 3
high 22
medium 11
low 2
unknown 0

Beta — feedback welcome: [email protected]