Skip to content
Tools / Ralph / Dependencies

Dependency Analysis

Ralph

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

74% Freshness
231 Dependencies
38 Outdated
0 Stale
3.2 Avg Behind

Dependency List

Latest release 20260506.1

Dependency Type Current Latest Behind CVE License
django
pypi
Direct 4.2.23 20 critical (Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND Python-2.0 AND Python-2.0.1) OR (BSD-3-Clause AND LicenseRef-scancode-other-permissive AND Python-2.0 AND Python-2.0.1)
cryptography
pypi
Direct 45.0.5 48.0.0 12 behind 3 high Apache-2.0 OR BSD-3-Clause OR (Apache-2.0 AND BSD-3-Clause)
urllib3
pypi
Direct 2.5.0 2.7.0 5 behind 3 high MIT
pillow
pypi
Direct 11.3.0 12.2.0 4 behind 6 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
pyjwt
pypi
Direct 2.10.1 2.13.0 4 behind 1 high MIT
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
setuptools
pypi
Direct 65.7.0 2 high MIT
werkzeug
pypi
Direct 0.16.1 10 high BSD-2-Clause AND BSD-3-Clause
requests
pypi
Direct 2.32.4 2.34.2 7 behind 1 medium Apache-2.0
sqlparse
pypi
Direct 0.5.3 0.5.5 2 behind 1 medium BSD-2-Clause AND BSD-3-Clause
markdown
pypi
Direct 3.2.1 1 medium BSD-2-Clause
python-ldap
pypi
Direct 3.4.4 2 medium python-ldap
social-auth-app-django
pypi
Direct 5.4.3 1 medium BSD-2-Clause AND BSD-3-Clause
pygments
pypi
Direct 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause
djangorestframework
pypi
Direct 3.15.0 1 low BSD-2-Clause AND BSD-3-Clause
pymdown-extensions
pypi
Direct 10.4 1 low MIT

License Breakdown

MIT 56
Unknown 46
BSD-2-Clause AND BSD-3-Clause 32
Apache-2.0 27
BSD-2-Clause 16
BSD-3-Clause 15
Apache-2.0 AND BSD-2-Clause 2
Apache-2.0 AND BSD-3-Clause 2
ISC 2
LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 2
MIT AND Python-2.0 2
MPL-2.0 2
(Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND Python-2.0 AND Python-2.0.1) OR (BSD-3-Clause AND LicenseRef-scancode-other-permissive AND Python-2.0 AND Python-2.0.1) 1
0BSD AND Apache-2.0 AND BSD-3-Clause AND MIT 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0 1
Apache-2.0 AND BSD-1-Clause AND BSD-2-Clause AND BSD-3-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND GPL-1.0-or-later AND GPL-2.0-only 1
Apache-2.0 AND Python-2.0 1
Apache-2.0 OR BSD-3-Clause OR (Apache-2.0 AND BSD-3-Clause) 1
Artistic-1.0 AND Artistic-1.0-Perl AND Artistic-2.0 1
BSD-2-Clause AND BSD-2-Clause-Views AND BSD-3-Clause 1
BSD-2-Clause AND BSD-3-Clause AND MIT 1
BSD-2-Clause AND MIT 1
BSD-3-Clause AND GPL-1.0-or-later AND GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later 1
BSD-3-Clause AND MIT 1
CNRI-Python AND Apache-2.0 1
GPL-2.0-only 1
GPL-3.0-or-later 1
LGPL-2.1-only 1
LGPL-3.0-only 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
MIT AND ZPL-2.1 1
PSF-2.0 1
Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Python-2.0.1 1
python-ldap 1

CVE Severity

critical 1
high 7
medium 5
low 3
unknown 0

Beta — feedback welcome: [email protected]