Skip to content
Tools / ragflow / Dependencies

Dependency Analysis

ragflow

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

54% Freshness
2439 Dependencies
928 Outdated
0 Stale
15.7 Avg Behind

Dependency List

Latest release v0.25.1

Dependency Type Current Latest Behind CVE License
lxml
pypi
Transitive 5.4.0 6.1.1 7 behind 1 high BSD-3-Clause AND GPL-1.0-or-later
dompurify
npm
Direct 3.3.2 3.4.8 10 behind 4 medium (Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0)
chardet
pypi
Direct 5.2.0 7.4.3 13 behind LGPL-2.1-or-later
pydivert
pypi
Transitive 2.1.0 3.1.3 5 behind GPL-3.0-or-later
docutils
pypi
Transitive 0.22.4 0.23.0 2 behind BSD-2-Clause AND BSD-3-Clause AND CC-PDDC AND GPL-1.0-or-later AND GPL-3.0-only AND GPL-3.0-or-later AND LicenseRef-scancode-free-unknown AND LicenseRef-scancode-other-copyleft AND LicenseRef-scancode-public-domain
lxml
pypi
Transitive 6.1.0 6.1.1 1 behind BSD-3-Clause AND GPL-1.0-or-later AND LicenseRef-scancode-unknown-license-reference
mysql-connector-python
pypi
Direct 9.6.0 9.7.0 1 behind GPL-2.0-only AND LicenseRef-scancode-unknown-license-reference
psycopg2-binary
pypi
Direct 2.9.11 2.9.12 1 behind LGPL-2.0-or-later AND LGPL-3.0-or-later
pygithub
pypi
Direct 2.9.0 2.9.1 1 behind GPL-3.0 AND GPL-3.0-only AND LGPL-3.0-only AND LGPL-3.0-or-later
crc32c
pypi
Transitive 2.8 2.8.0 BSD-2-Clause AND BSD-3-Clause AND LGPL-2.1-only AND LGPL-2.1-or-later
datrie
pypi
Transitive 0.8.3 0.8.3 Current LGPL-2.0-or-later AND LGPL-2.1-only
demjson3
pypi
Direct 3.0.6 3.0.6 Current GPL-3.0-or-later AND LGPL-2.0-or-later AND LGPL-3.0-only
extract-msg
pypi
Direct 0.55.0 0.55.0 Current GPL-3.0-only AND GPL-3.0-or-later
frozendict
pypi
Transitive 2.4.7 2.4.7 Current LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later
gensim
pypi
Transitive 4.4.0 4.4.0 Current LGPL-2.1-only
jszip
npm
Transitive 3.10.1 3.10.1 Current GPL-3.0-only OR MIT
pcodedmp
pypi
Transitive 1.2.6 1.2.6 Current GPL-1.0-or-later AND GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later
pot
pypi
Transitive 0.9.6.post1 0.9.6.post1 Current GPL-1.0-or-later AND GPL-3.0-only AND MIT
rtfde
pypi
Transitive 0.1.2.2 0.1.2.2 Current LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later
shapely
pypi
Transitive 2.1.2 2.1.2 Current BSD-3-Clause AND LGPL-2.1-only
text-unidecode
pypi
Transitive 1.3 1.3.0 Artistic-1.0-Perl OR GPL-1.0-only OR GPL-2.0-or-later
typing-extensions
pypi
Transitive 4.15.0 4.15.0 Current Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD
typing-extensions
pypi
Transitive 4.15.0 4.15.0 Current Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD
warc3-wet
pypi
Transitive 0.2.5 0.2.5 Current GPL-2.0-only
warc3-wet-clueweb09
pypi
Transitive 0.2.5 0.2.5 Current GPL-3.0-or-later

License Breakdown

MIT 1706
Apache-2.0 179
Unknown 110
ISC 88
BSD-3-Clause 87
BSD-2-Clause 59
BSD-2-Clause AND BSD-3-Clause 33
Apache-2.0 AND MIT 20
MPL-2.0 9
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 8
ISC AND MIT 7
Apache-2.0 AND BSD-2-Clause 6
Apache-2.0 AND BSD-3-Clause 4
LicenseRef-scancode-generic-cla AND MIT 4
MIT AND MPL-2.0 4
MIT AND Python-2.0 4
0BSD 3
BSD-3-Clause AND MIT 3
CC0-1.0 3
CC0-1.0 AND MIT 3
0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0 2
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 2
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 2
Apache-2.0 OR (Apache-2.0 AND MIT) 2
Apache-2.0 OR BSD-3-Clause OR (Apache-2.0 AND BSD-3-Clause) 2
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain AND Unlicense 2
BSD-2-Clause AND BSD-3-Clause AND MIT 2
GPL-3.0-or-later 2
LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 2
LicenseRef-scancode-free-unknown AND MIT 2
LicenseRef-scancode-proprietary-license AND MIT 2
LicenseRef-scancode-public-domain AND Unlicense 2
MIT AND MIT-0 2
MIT AND PSF-2.0 2
MIT AND Zlib 2
PSF-2.0 2
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 2
Unlicense 2
(Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0) 1
0BSD AND BSD-2-Clause AND BSD-3-Clause 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
0BSD AND ISC AND MIT 1
Apache-2.0 AND BSD-3-Clause AND CC-BY-4.0 AND LicenseRef-scancode-warranty-disclaimer 1
Apache-2.0 AND BSD-3-Clause AND FSFAP-no-warranty-disclaimer AND LicenseRef-scancode-public-domain-disclaimer AND MIT 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MIT 1
Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1 1
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 1
Apache-2.0 AND ISC 1
Apache-2.0 AND LicenseRef-scancode-generic-cla 1
Artistic-1.0-Perl OR GPL-1.0-only OR GPL-2.0-or-later 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-2-Clause AND BSD-3-Clause AND BSD-Advertising-Acknowledgement 1
BSD-2-Clause AND BSD-3-Clause AND CC-PDDC AND GPL-1.0-or-later AND GPL-3.0-only AND GPL-3.0-or-later AND LicenseRef-scancode-free-unknown AND LicenseRef-scancode-other-copyleft AND LicenseRef-scancode-public-domain 1
BSD-2-Clause AND BSD-3-Clause AND LGPL-2.1-only AND LGPL-2.1-or-later 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain-disclaimer AND MIT 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 1
BSD-2-Clause AND LicenseRef-scancode-other-permissive 1
BSD-2-Clause AND Python-2.0 1
BSD-2-Clause-FreeBSD AND BSD-2-Clause-Views 1
BSD-3-Clause AND 0BSD AND CC0-1.0 AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause AND GPL-1.0-or-later 1
BSD-3-Clause AND GPL-1.0-or-later AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause AND ISC 1
BSD-3-Clause AND ISC AND MIT 1
BSD-3-Clause AND LGPL-2.1-only 1
BSD-3-Clause AND LicenseRef-scancode-generic-cla AND MIT 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause AND MIT AND MIT-0 1
BSL-1.0 AND MIT 1
BlueOak-1.0.0 1
CC-BY-4.0 1
CNRI-Python AND Apache-2.0 1
GPL-1.0-or-later AND GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later 1
GPL-1.0-or-later AND GPL-3.0-only AND MIT 1
GPL-2.0-only 1
GPL-2.0-only AND LicenseRef-scancode-unknown-license-reference 1
GPL-3.0 AND GPL-3.0-only AND LGPL-3.0-only AND LGPL-3.0-or-later 1
GPL-3.0-only AND GPL-3.0-or-later 1
GPL-3.0-only OR MIT 1
GPL-3.0-or-later AND LGPL-2.0-or-later AND LGPL-3.0-only 1
ISC AND JSON AND MIT 1
ISC AND LicenseRef-scancode-unknown-license-reference AND MIT AND MIT-Wu 1
LGPL-2.0-or-later AND LGPL-2.1-only 1
LGPL-2.0-or-later AND LGPL-3.0-or-later 1
LGPL-2.1-only 1
LGPL-2.1-or-later 1
LicenseRef-scancode-commercial-license AND LicenseRef-scancode-other-permissive AND MIT 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
LicenseRef-scancode-unknown-license-reference AND BSD-3-Clause 1
MIT AND CC0-1.0 1
MIT AND HPND-Markus-Kuhn 1
MIT AND OFL-1.1 1
MIT AND Unlicense 1
MIT AND ZPL-2.1 1
MIT-0 1
MIT-CMU 1
Python-2.0 1
Python-2.0.1 1

CVE Severity

critical 2
high 31
medium 19
low 5
unknown 2

Beta — feedback welcome: [email protected]