Skip to content
Tools / phoenix / Dependencies

Dependency Analysis

phoenix

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

47% Freshness
4516 Dependencies
1855 Outdated
0 Stale
10.7 Avg Behind

Dependency List

Latest release arize-phoenix-v15.4.0

Dependency Type Current Latest Behind CVE License
litellm
pypi
Direct 1.82.6 1.88.0.dev1 37 behind 6 critical LicenseRef-scancode-commercial-license AND LicenseRef-scancode-other-permissive AND MIT
protobufjs
npm
Transitive 7.5.4 8.5.0 20 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
protobufjs
npm
Transitive 7.5.4 8.5.0 20 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
protobufjs
npm
Transitive 7.5.4 8.5.0 20 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
vite
npm
Direct 8.0.2 8.0.16 17 behind 3 high Apache-2.0 AND BSD-2-Clause AND CC0-1.0 AND ISC AND MIT
fast-xml-builder
npm
Transitive 1.1.4 1.2.0 6 behind 1 high MIT
path-to-regexp
npm
Transitive 0.1.12 8.4.2 5 behind 1 high MIT
jupyter-server
pypi
Transitive 2.17.0 2.19.0 4 behind 4 high BSD-3-Clause
path-to-regexp
npm
Transitive 8.3.0 8.4.2 4 behind 2 high MIT
path-to-regexp
npm
Transitive 8.3.0 8.4.2 4 behind 2 high MIT
gitpython
pypi
Direct 3.1.47 3.1.50 3 behind 2 high Unknown
notebook
pypi
Transitive 7.5.5 7.5.6 3 behind 2 high Unknown
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
picomatch
npm
Transitive 4.0.3 4.0.4 3 behind 2 high MIT
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
jupyterlab
pypi
Transitive 4.5.6 4.5.7 2 behind 3 high Unknown
lodash
npm
Direct 4.17.23 4.18.1 2 behind 2 high CC0-1.0 AND MIT
lodash-es
npm
Transitive 4.17.23 4.18.1 2 behind 2 high MIT
mako
pypi
Transitive 1.3.11 1.3.12 1 behind 1 high MIT
mistune
pypi
Transitive 3.2.0 3.2.1 1 behind 1 high BSD-3-Clause
pillow
pypi
Direct 12.1.1 12.2.0 1 behind 5 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
streamlit
pypi
Direct 1.37.0 1.58.0 40 behind 1 medium Apache-2.0
langsmith
npm
Transitive 0.5.5 0.7.4 30 behind 2 medium MIT
hono
npm
Transitive 4.12.9 4.12.23 14 behind 8 medium MIT
nodemailer
npm
Transitive 7.0.13 8.0.10 11 behind 2 medium MIT AND MIT-0
@hono/node-server
npm
Transitive 1.19.11 2.0.4 10 behind 1 medium MIT
fast-xml-parser
npm
Transitive 5.5.9 5.8.0 10 behind 1 medium MIT
dompurify
npm
Transitive 3.3.3 3.4.8 9 behind 4 medium (Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0)
brace-expansion
npm
Transitive 5.0.4 5.0.6 7 behind 1 medium MIT
brace-expansion
npm
Transitive 5.0.4 5.0.6 7 behind 1 medium MIT
postcss
npm
Transitive 8.5.8 8.5.15 7 behind 1 medium MIT
postcss
npm
Transitive 8.5.8 8.5.15 7 behind 1 medium MIT
postcss
npm
Transitive 8.5.8 8.5.15 7 behind 1 medium MIT
requests
pypi
Direct 2.32.4 2.34.2 7 behind 1 medium Apache-2.0
requests
pypi
Direct 2.32.4 2.34.2 7 behind 1 medium Apache-2.0
yaml
npm
Transitive 2.8.1 2.9.0 7 behind 1 medium ISC
python-dotenv
pypi
Direct 1.0.1 1.2.2 5 behind 1 medium BSD-2-Clause AND BSD-3-Clause
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
uuid
npm
Transitive 11.1.0 14.0.0 3 behind 1 medium MIT
ip-address
npm
Transitive 10.1.0 10.2.0 2 behind 1 medium MIT
idna
pypi
Direct 3.6 3.18.0 1 medium BSD-3-Clause
idna
pypi
Direct 3.6 3.18.0 1 medium BSD-3-Clause
pyarrow
pypi
Direct 15.0.2 24.0.0 13 behind 1 unknown Apache-2.0

License Breakdown

MIT 2984
Unknown 508
Apache-2.0 417
ISC 173
BSD-3-Clause 130
MPL-2.0 53
BSD-2-Clause 39
BlueOak-1.0.0 35
BSD-2-Clause AND BSD-3-Clause 33
Apache-2.0 AND MIT 11
BSD-3-Clause AND LicenseRef-scancode-protobuf 5
CC-BY-4.0 5
CC0-1.0 AND MIT 5
MIT-0 5
0BSD AND ISC AND MIT 4
Apache-2.0 AND BSD-2-Clause 4
BSD-3-Clause AND MIT 4
Apache-2.0 OR (Apache-2.0 AND LGPL-3.0-only) 3
BSD-2-Clause AND BSD-3-Clause AND MIT 3
BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 3
CC0-1.0 3
ISC AND MIT 3
LicenseRef-scancode-generic-cla AND MIT 3
LicenseRef-scancode-unknown-license-reference AND MIT 3
MIT AND MPL-2.0 3
0BSD 2
AFL-2.1 AND AFL-3.0 AND BSD-3-Clause 2
Apache-2.0 AND BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 2
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 2
Apache-2.0 AND Elastic-2.0 2
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 2
BSD-2-Clause AND BSD-2-Clause-Views 2
BSD-3-Clause AND ISC AND MIT 2
BSD-3-Clause AND LicenseRef-scancode-generic-cla AND MIT 2
Elastic-2.0 2
ISC AND JSON AND MIT 2
LGPL-2.1-only AND MIT AND MPL-1.1 2
LGPL-3.0-or-later 2
LicenseRef-scancode-free-unknown AND MIT 2
MIT AND Python-2.0 2
PSF-2.0 2
Python-2.0 2
Python-2.0.1 2
(Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0) 1
(MIT OR EUPL-1.1+) 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 1
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 1
Apache-2.0 AND GPL-1.0-or-later AND MIT 1
Apache-2.0 AND ISC 1
Apache-2.0 AND MIT AND MPL-2.0 1
Apache-2.0 OR (Apache-2.0 AND BSD-3-Clause) 1
Artistic-1.0-Perl OR GPL-1.0-only OR GPL-2.0-or-later 1
BSD-2-Clause AND BSD-3-Clause AND CC-PDDC AND GPL-1.0-or-later AND GPL-3.0-only AND GPL-3.0-or-later AND LicenseRef-scancode-free-unknown AND LicenseRef-scancode-other-copyleft AND LicenseRef-scancode-public-domain 1
BSD-2-Clause AND JSON 1
BSD-2-Clause AND MIT AND Python-2.0 AND Python-2.0.1 1
BSD-3-Clause AND CC0-1.0 AND ISC AND MIT 1
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause OR Apache-2.0 1
BSD-3-Clause OR MIT OR (BSD-3-Clause AND MIT) 1
CC-BY-SA-3.0 AND MIT AND Python-2.0 1
CC0-1.0 AND Unlicense 1
CC0-1.0 OR MIT OR (CC0-1.0 AND MIT) 1
CNRI-Python AND Apache-2.0 1
GPL-2.0-only AND GPL-2.0-or-later 1
ISC AND MPL-2.0 1
LGPL-2.1-or-later 1
LGPL-3.0 1
LGPL-3.0 AND LGPL-3.0-only 1
LicenseRef-scancode-commercial-license AND LicenseRef-scancode-other-permissive AND MIT 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
LicenseRef-scancode-unknown-license-reference AND MIT AND Python-2.0 1
MIT AND CC0-1.0 1
MIT AND HPND-Markus-Kuhn 1
MIT AND MIT-0 1
MIT AND PSF-2.0 1
MIT AND Ruby 1
MIT AND WTFPL 1
MIT AND ZPL-2.1 1
MIT OR (MIT AND WTFPL) 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Unlicense 1
apache-2.0 1

CVE Severity

critical 4
high 20
medium 21
low 0
unknown 1

Beta — feedback welcome: [email protected]