Skip to content
Tools / Raneto / Dependencies

Dependency Analysis

Raneto

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

59% Freshness
679 Dependencies
215 Outdated
0 Stale
5.3 Avg Behind

Dependency List

Latest release 0.18.1

Dependency Type Current Latest Behind CVE License
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
path-to-regexp
npm
Transitive 8.3.0 8.4.2 4 behind 2 high MIT
lodash
npm
Direct 4.17.23 4.18.1 2 behind 2 high CC0-1.0 AND MIT
brace-expansion
npm
Transitive 1.1.12 5.0.6 10 behind 1 medium MIT
postcss
npm
Transitive 8.5.8 8.5.15 7 behind 1 medium MIT
ip-address
npm
Transitive 10.1.0 10.2.0 2 behind 1 medium MIT

License Breakdown

MIT 559
ISC 40
Apache-2.0 21
BSD-3-Clause 15
BSD-2-Clause 9
BlueOak-1.0.0 9
Unknown 8
Apache-2.0 AND MIT 2
CC0-1.0 AND MIT 2
ISC AND MIT 2
0BSD 1
Apache-2.0 AND BSD-2-Clause 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-2-Clause AND BSD-3-Clause 1
CC-BY-4.0 1
ISC OR WTFPL OR (ISC AND WTFPL) 1
LicenseRef-scancode-free-unknown AND MPL-1.1 1
MIT AND Zlib 1
MIT OR WTFPL OR (MIT AND WTFPL) 1
Python-2.0 1
WTFPL 1

CVE Severity

critical 0
high 3
medium 3
low 0
unknown 0

Beta — feedback welcome: [email protected]