Skip to content
Tools / Pomerium / Dependencies

Dependency Analysis

Pomerium

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

81% Freshness
908 Dependencies
146 Outdated
0 Stale
32.7 Avg Behind

Dependency List

Latest release v0.32.6

Dependency Type Current Latest Behind CVE License
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
brace-expansion
npm
Transitive 2.0.2 5.0.6 11 behind 1 medium MIT
diff
npm
Transitive 4.0.2 9.0.0 18 behind 1 low BSD-3-Clause
golang.org/x/image
golang
Direct v0.38.0 2 unknown Unknown

License Breakdown

MIT 480
Apache-2.0 159
Unknown 103
BSD-3-Clause 46
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 21
ISC 20
Apache-2.0 AND BSD-3-Clause 17
BSD-2-Clause 13
MPL-2.0 9
Apache-2.0 AND MIT 5
LicenseRef-scancode-generic-cla AND MIT 4
Apache-2.0 AND BSD-3-Clause AND MIT 3
BSD-3-Clause AND MIT 3
Apache-2.0 AND CC-BY-SA-4.0 2
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 2
BSD-2-Clause AND BSD-3-Clause 2
MIT-0 2
OFL-1.1 2
0BSD 1
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause 1
Apache-2.0 AND CC-BY-4.0 AND MIT 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 1
BSD-1-Clause 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-2-Clause-Views 1
CC-BY-4.0 1
CC0-1.0 1
CC0-1.0 AND LicenseRef-scancode-public-domain 1
CC0-1.0 AND MIT 1
FTL OR GPL-2.0-or-later 1
Python-2.0 1

CVE Severity

critical 0
high 0
medium 2
low 1
unknown 1

Beta — feedback welcome: [email protected]