Skip to content
Tools / Ralph / Dependencies

Dependency Analysis

Ralph

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

74% Freshness
231 Dependencies
38 Outdated
0 Stale
3.2 Avg Behind

Dependency List

Latest release 20260506.1

Dependency Type Current Latest Behind CVE License
django
pypi
Direct 4.2.23 20 critical (Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND Python-2.0 AND Python-2.0.1) OR (BSD-3-Clause AND LicenseRef-scancode-other-permissive AND Python-2.0 AND Python-2.0.1)
cryptography
pypi
Direct 45.0.5 48.0.0 12 behind 3 high Apache-2.0 OR BSD-3-Clause OR (Apache-2.0 AND BSD-3-Clause)
urllib3
pypi
Direct 2.5.0 2.7.0 5 behind 3 high MIT
pillow
pypi
Direct 11.3.0 12.2.0 4 behind 6 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
pyjwt
pypi
Direct 2.10.1 2.13.0 4 behind 1 high MIT
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
setuptools
pypi
Direct 65.7.0 2 high MIT
werkzeug
pypi
Direct 0.16.1 10 high BSD-2-Clause AND BSD-3-Clause
requests
pypi
Direct 2.32.4 2.34.2 7 behind 1 medium Apache-2.0
sqlparse
pypi
Direct 0.5.3 0.5.5 2 behind 1 medium BSD-2-Clause AND BSD-3-Clause
markdown
pypi
Direct 3.2.1 1 medium BSD-2-Clause
python-ldap
pypi
Direct 3.4.4 2 medium python-ldap
social-auth-app-django
pypi
Direct 5.4.3 1 medium BSD-2-Clause AND BSD-3-Clause
pygments
pypi
Direct 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause
djangorestframework
pypi
Direct 3.15.0 1 low BSD-2-Clause AND BSD-3-Clause
pymdown-extensions
pypi
Direct 10.4 1 low MIT
sphinx
pypi
Direct 7.3.7 9.1.0 35 behind BSD-2-Clause AND BSD-3-Clause
coverage
pypi
Direct 7.9.2 7.14.1 23 behind Apache-2.0
regex
pypi
Direct 2024.11.6 2026.5.9 17 behind CNRI-Python AND Apache-2.0
ipython
pypi
Direct 8.37.0 9.14.0 14 behind BSD-3-Clause
docutils
pypi
Direct 0.21.2 0.23.0 13 behind BSD-2-Clause
platformdirs
pypi
Direct 4.3.8 4.10.0 13 behind MIT
wcwidth
pypi
Direct 0.2.13 0.7.0 13 behind MIT
gunicorn
pypi
Direct 23.0.0 26.0.0 11 behind MIT
certifi
pypi
Direct 2025.6.15 2026.5.20 9 behind MPL-2.0
rich
pypi
Direct 14.0.0 15.0.0 8 behind MIT
click
pypi
Direct 8.2.1 8.4.1 7 behind BSD-3-Clause
pathspec
pypi
Direct 0.12.1 1.1.1 7 behind MPL-2.0
psutil
pypi
Direct 7.0.0 7.2.2 7 behind BSD-3-Clause
pyparsing
pypi
Direct 3.2.3 3.3.2 7 behind MIT AND Python-2.0
rpds-py
pypi
Direct 0.26.0 2026.5.1 6 behind MIT
charset-normalizer
pypi
Direct 3.4.2 3.4.7 5 behind MIT
prometheus-client
pypi
Direct 0.22.1 0.25.0 5 behind Apache-2.0 AND BSD-2-Clause
jsonschema
pypi
Direct 4.24.0 4.26.0 4 behind MIT
requests-oauthlib
pypi
Direct 1.3.0 2.0.0 4 behind BSD-2-Clause
markdown-it-py
pypi
Direct 3.0.0 4.2.0 3 behind MIT
parso
pypi
Direct 0.8.4 0.8.7 3 behind MIT
tblib
pypi
Direct 3.1.0 3.2.2 3 behind BSD-2-Clause AND BSD-3-Clause
tomli
pypi
Direct 2.2.1 2.4.1 3 behind MIT
attrs
pypi
Direct 25.3.0 26.1.0 2 behind MIT
cffi
pypi
Direct 1.17.1 2.0.0 2 behind MIT
decorator
pypi
Direct 5.2.1 5.3.1 2 behind BSD-2-Clause AND BSD-3-Clause
imagesize
pypi
Direct 1.4.1 2.0.0 2 behind MIT
jsonpointer
pypi
Direct 3.0.0 3.1.1 2 behind BSD-3-Clause
matplotlib-inline
pypi
Direct 0.1.7 0.2.2 2 behind BSD-2-Clause AND BSD-3-Clause
pyperclip
pypi
Direct 1.9.0 1.11.0 2 behind BSD-2-Clause AND BSD-3-Clause
snowballstemmer
pypi
Direct 3.0.1 3.1.1 2 behind BSD-3-Clause
toml-sort
pypi
Direct 0.24.2 0.24.4 2 behind MIT
tomlkit
pypi
Direct 0.13.3 0.15.0 2 behind MIT
traitlets
pypi
Direct 5.14.3 5.15.1 2 behind BSD-3-Clause
typing-extensions
pypi
Direct 4.14.1 4.15.0 2 behind Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD
alabaster
pypi
Direct 0.7.16 1.0.0 1 behind BSD-2-Clause AND BSD-3-Clause
asttokens
pypi
Direct 3.0.0 3.0.1 1 behind Apache-2.0
exceptiongroup
pypi
Direct 1.3.0 1.3.1 1 behind MIT AND Python-2.0
executing
pypi
Direct 2.2.0 2.2.1 1 behind MIT
jedi
pypi
Direct 0.19.2 0.20.0 1 behind MIT
jmespath
pypi
Direct 1.0.1 1.1.0 1 behind MIT
jsonschema-specifications
pypi
Direct 2025.4.1 2025.9.1 1 behind MIT
markupsafe
pypi
Direct 3.0.2 3.0.3 1 behind BSD-2-Clause AND BSD-3-Clause
prompt-toolkit
pypi
Direct 3.0.51 3.0.52 1 behind BSD-2-Clause AND BSD-3-Clause
python-dateutil
pypi
Direct 2.9.0 2.9.0.post0 1 behind Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference
pyyaml
pypi
Direct 6.0.2 6.0.3 1 behind MIT
referencing
pypi
Direct 0.36.2 0.37.0 1 behind MIT
six
pypi
Direct 1.16.0 1.17.0 1 behind MIT
actions/checkout
githubactions
Direct 2.*.* Unknown
appdirs
pypi
Direct 1.4.4 1.4.4 Current MIT
argparse
pypi
Direct 1.4.0 1.4.0 Current Python-2.0.1
asgiref
pypi
Direct 3.9.0 BSD-3-Clause
async-timeout
pypi
Direct 5.0.1 5.0.1 Current Apache-2.0
autopage
pypi
Direct 0.5.2 Apache-2.0
babel
pypi
Direct 2.11.0 BSD-2-Clause AND BSD-3-Clause
bower
npm
Direct ^1.8.14 Unknown
cliff
pypi
Direct 4.10.0 Apache-2.0
cmd2
pypi
Direct 2.7.0 MIT
colorama
pypi
Direct 0.4.6 0.4.6 Current BSD-2-Clause AND BSD-3-Clause
coveralls
pypi
Direct 4.0.1 MIT
ddt
pypi
Direct 1.7.2 MIT
debtcollector
pypi
Direct 1.3.0 Apache-2.0
defusedxml
pypi
Direct 0.7.1 0.7.1 Current PSF-2.0
del
npm
Direct ^6.1.1 Unknown
diff-match-patch
pypi
Direct 20241021 Apache-2.0
django
Direct Unknown
django-appconf
pypi
Direct 1.1.0 BSD-2-Clause AND BSD-3-Clause
django-auth-ldap
pypi
Direct 2.4.0 BSD-2-Clause
django-auth-ldap
Direct Unknown
django-cors-headers
pypi
Direct 4.7.0 MIT
django-cryptography-django5
pypi
Direct 2.2 BSD-2-Clause AND BSD-3-Clause
django-cryptography-django5
Direct Unknown
django-debug-toolbar
pypi
Direct 5.2.0 BSD-3-Clause
django-extensions
pypi
Direct 3.1.5 MIT
django-filter
pypi
Direct 25.1 25.2.0 BSD-2-Clause AND BSD-3-Clause
django-import-export
pypi
Direct 4.0.2 BSD-2-Clause
django-import-export
Direct Unknown
django-js-asset
pypi
Direct 3.1.2 BSD-3-Clause
django-money
pypi
Direct 3.4.1 BSD-2-Clause AND BSD-3-Clause
django-mptt
pypi
Direct 0.14.0 MIT
django-mptt
pypi
Direct 0.14 Unknown
django-plainpasswordhasher
pypi
Direct 0.3 BSD-2-Clause
django-prometheus
pypi
Direct 2.2.0 Apache-2.0
django-redis
pypi
Direct 5.0.0 BSD-2-Clause AND BSD-3-Clause
django-reversion
pypi
Direct 4.0.2 BSD-2-Clause AND BSD-3-Clause
django-reversion
Direct Unknown
django-rq
pypi
Direct 2.8.0 MIT
django-silk
pypi
Direct 5.4.0 MIT
django-sitetree
pypi
Direct 1.18.0 BSD-2-Clause AND BSD-3-Clause
django-taggit
pypi
Direct 3.1.0 BSD-2-Clause AND BSD-3-Clause
django-taggit
Direct Unknown
django-threadlocals
pypi
Direct 0.8 BSD-2-Clause
djangorestframework-xml
pypi
Direct 2.0.0 BSD-2-Clause
docopt
pypi
Direct 0.6.2 0.6.2 Current MIT
dogpile-cache
pypi
Direct 1.3.4 Unknown
drf-nested-routers
pypi
Direct 0.92.5 Apache-2.0
et-xmlfile
pypi
Direct 2.0.0 2.0.0 Current 0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0
factory-boy
pypi
Direct 3.2.1 MIT
faker
pypi
Direct 0.9.0 MIT
funcsigs
pypi
Direct 0.4 Apache-2.0
ghp-import
pypi
Direct 2.1.0 2.1.0 Current Apache-2.0
gnureadline
pypi
Direct 8.2.13 BSD-3-Clause AND GPL-1.0-or-later AND GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later
gprof2dot
pypi
Direct 2025.4.14 2025.4.14 Current LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later
gulp
npm
Direct ^4.0.2 5.0.1 Unknown
gulp-autoprefixer
npm
Direct ^8.0.0 Unknown
gulp-bower
npm
Direct ^0.0.15 Unknown
gulp-rename
npm
Direct ^2.0.0 Unknown
gulp-sass
npm
Direct ^5.1.0 Unknown
gulp-sourcemaps
npm
Direct ^3.0.0 Unknown
gulp-vulcanize
npm
Direct ^8.0.0 Unknown
gulp-watch
npm
Direct ^5.0.1 Unknown
hiredis
pypi
Direct 3.2.1 BSD-3-Clause AND MIT
hiredis
Direct >= 3.1.0 Unknown
idna
pypi
Direct 3.10 3.18.0 BSD-3-Clause
ipdb
pypi
Direct 0.13.13 BSD-2-Clause AND BSD-3-Clause
iso8601
pypi
Direct 0.1.11 MIT
jdcal
pypi
Direct 1.4.1 BSD-2-Clause
jinja2
pypi
Direct 3.1.6 3.1.6 Current BSD-2-Clause AND BSD-3-Clause
jshint
npm
Direct ^2.13.6 Unknown
jsonpatch
pypi
Direct 1.33 1.33.0 BSD-3-Clause
keystoneauth1
pypi
Direct 5.8.1 Apache-2.0 AND BSD-3-Clause
keystoneauth1
Direct Unknown
mdurl
pypi
Direct 0.1.2 0.1.2 Current MIT
mergedeep
pypi
Direct 1.3.4 1.3.4 Current MIT
mkdocs
pypi
Direct 1.5.3 BSD-2-Clause AND BSD-3-Clause
mkdocs-bootstrap
pypi
Direct 1.1.1 BSD-2-Clause AND BSD-2-Clause-Views AND BSD-3-Clause
mkdocs-bootswatch
pypi
Direct 1.1 BSD-2-Clause AND MIT
mkdocs-material
pypi
Direct 9.5.18 MIT
mkdocs-material-extensions
pypi
Direct 1.3.1 1.3.1 Current MIT
mock
pypi
Direct 4.0.2 BSD-2-Clause
monotonic
pypi
Direct 0.6 Apache-2.0
msgpack
pypi
Direct 1.1.1 Apache-2.0
msgpack-python
pypi
Direct 0.4.7 Apache-2.0
mysqlclient
pypi
Direct 2.0.3 GPL-2.0-only
mysqlclient
Direct Unknown
netaddr
pypi
Direct 0.10.1 BSD-2-Clause AND BSD-3-Clause AND MIT
netifaces
pypi
Direct 0.11.0 0.11.0 Current MIT
netifaces
Direct Unknown
oauthlib
pypi
Direct 3.3.1 3.3.1 Current BSD-3-Clause
odfpy
pypi
Direct 1.4.1 1.4.1 Current Apache-2.0 AND GPL-1.0-or-later AND GPL-2.0-only
odfpy
Direct >= 1.4.1 Unknown
openpyxl
pypi
Direct 2.6.4 MIT
openpyxl
Direct Unknown
openstacksdk
pypi
Direct 1.5.0 Apache-2.0
os-service-types
pypi
Direct 1.7.0 Apache-2.0
osc-lib
pypi
Direct 4.0.2 Apache-2.0
oslo-config
pypi
Direct 9.7.1 Unknown
oslo-i18n
pypi
Direct 6.5.1 Unknown
oslo-serialization
pypi
Direct 5.7.0 Unknown
oslo-utils
pypi
Direct 8.2.0 Unknown
packaging
pypi
Direct 25.0 26.2.0 Apache-2.0 AND BSD-2-Clause
paginate
pypi
Direct 0.5.7 0.5.7 Current MIT
pbr
pypi
Direct 6.1.1 Apache-2.0
pbr
Direct Unknown
pexpect
pypi
Direct 4.9.0 4.9.0 Current ISC
pillow
Direct Unknown
positional
pypi
Direct 1.0.1 Apache-2.0
prettytable
pypi
Direct 0.7.2 BSD-2-Clause AND BSD-3-Clause
psycopg
pypi
Direct 3.2.10 LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later
psycopg
Direct Unknown
psycopg-binary
pypi
Direct 3.2.10 Unknown
psycopg-pool
pypi
Direct 3.2.7 LGPL-3.0-only
ptyprocess
pypi
Direct 0.7.0 0.7.0 Current ISC
pudb
pypi
Direct 2025.1 MIT
pure-eval
pypi
Direct 0.2.3 0.2.3 Current MIT
py-moneyed
pypi
Direct 3.0 BSD-2-Clause AND BSD-3-Clause
pyasn1-modules
pypi
Direct 0.4.2 0.4.2 Current BSD-2-Clause AND BSD-3-Clause
pycparser
pypi
Direct 2.22 3.0.0 BSD-3-Clause
pyhermes
pypi
Direct 0.6.0 Apache-2.0
pyhermes
Direct Unknown
python-ironicclient
pypi
Direct 5.12.0 Apache-2.0
python-ironicclient
Direct Unknown
python-keystoneclient
pypi
Direct 5.6.0 Apache-2.0 AND BSD-3-Clause
python-keystoneclient
Direct Unknown
python-novaclient
pypi
Direct 3.2.0 Apache-2.0 AND BSD-1-Clause AND BSD-2-Clause AND BSD-3-Clause
python3-openid
pypi
Direct 3.2.0 Apache-2.0
pytz
pypi
Direct 2025.1 2026.2.0 MIT AND ZPL-2.1
pyyaml-env-tag
pypi
Direct 1.1 1.1.0 MIT
raven
pypi
Direct 6.10.0 BSD-3-Clause
raven
Direct Unknown
redis
pypi
Direct 4.6.0 MIT
redis
Direct Unknown
requestsexceptions
pypi
Direct 1.4.0 Apache-2.0
rfc3986
pypi
Direct 2.0.0 2.0.0 Current Apache-2.0
rich-argparse
pypi
Direct 1.7.1 MIT
rq
pypi
Direct 1.16.2 BSD-2-Clause AND BSD-3-Clause
ruff
pypi
Direct 0.12.2 0BSD AND Apache-2.0 AND BSD-3-Clause AND MIT
sass
npm
Direct 1.32.13 MIT
setuptools
Direct < 66.0 Unknown
simplejson
pypi
Direct 3.8.2 Unknown
social-auth-app-django
Direct >= 5.4.3 Unknown
social-auth-core
pypi
Direct 4.7.0 BSD-3-Clause
sphinxcontrib-applehelp
pypi
Direct 2.0.0 2.0.0 Current BSD-2-Clause AND BSD-3-Clause
sphinxcontrib-devhelp
pypi
Direct 2.0.0 2.0.0 Current BSD-2-Clause
sphinxcontrib-htmlhelp
pypi
Direct 2.1.0 2.1.0 Current BSD-2-Clause
sphinxcontrib-jsmath
pypi
Direct 1.0.1 1.0.1 Current BSD-2-Clause
sphinxcontrib-qthelp
pypi
Direct 2.0.0 2.0.0 Current BSD-2-Clause AND BSD-3-Clause
sphinxcontrib-serializinghtml
pypi
Direct 2.0.0 2.0.0 Current BSD-2-Clause AND BSD-3-Clause
stack-data
pypi
Direct 0.6.3 0.6.3 Current MIT
statsd
pypi
Direct 3.3.0 MIT
statsd
Direct < 4.0.0 Unknown
stevedore
pypi
Direct 5.4.1 Apache-2.0
stevedore
Direct Unknown
tablib
pypi
Direct 3.5.0 MIT
tblib
Direct >= 3.1.0 Unknown
text-unidecode
pypi
Direct 1.2 Artistic-1.0 AND Artistic-1.0-Perl AND Artistic-2.0
typing
pypi
Direct 3.6.6 Python-2.0
tzdata
pypi
Direct 2025.2 2026.2.0 Apache-2.0
unidecode
pypi
Direct 0.4.18 Unknown
unidecode
pypi
Direct 0.04.18 GPL-3.0-or-later
urwid
pypi
Direct 3.0.2 LGPL-2.1-only
urwid-readline
pypi
Direct 0.15.1 MIT
watchdog
pypi
Direct 6.0.0 6.0.0 Current Apache-2.0 AND Python-2.0
wrapt
pypi
Direct 1.10.6 BSD-2-Clause

License Breakdown

MIT 56
Unknown 46
BSD-2-Clause AND BSD-3-Clause 32
Apache-2.0 27
BSD-2-Clause 16
BSD-3-Clause 15
Apache-2.0 AND BSD-2-Clause 2
Apache-2.0 AND BSD-3-Clause 2
ISC 2
LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 2
MIT AND Python-2.0 2
MPL-2.0 2
(Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND Python-2.0 AND Python-2.0.1) OR (BSD-3-Clause AND LicenseRef-scancode-other-permissive AND Python-2.0 AND Python-2.0.1) 1
0BSD AND Apache-2.0 AND BSD-3-Clause AND MIT 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0 1
Apache-2.0 AND BSD-1-Clause AND BSD-2-Clause AND BSD-3-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND GPL-1.0-or-later AND GPL-2.0-only 1
Apache-2.0 AND Python-2.0 1
Apache-2.0 OR BSD-3-Clause OR (Apache-2.0 AND BSD-3-Clause) 1
Artistic-1.0 AND Artistic-1.0-Perl AND Artistic-2.0 1
BSD-2-Clause AND BSD-2-Clause-Views AND BSD-3-Clause 1
BSD-2-Clause AND BSD-3-Clause AND MIT 1
BSD-2-Clause AND MIT 1
BSD-3-Clause AND GPL-1.0-or-later AND GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later 1
BSD-3-Clause AND MIT 1
CNRI-Python AND Apache-2.0 1
GPL-2.0-only 1
GPL-3.0-or-later 1
LGPL-2.1-only 1
LGPL-3.0-only 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
MIT AND ZPL-2.1 1
PSF-2.0 1
Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Python-2.0.1 1
python-ldap 1

CVE Severity

critical 1
high 7
medium 5
low 3
unknown 0

Beta — feedback welcome: [email protected]