Skip to content
Tools / reitti / Dependencies

Dependency Analysis

reitti

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

100% Freshness
203 Dependencies
0 Outdated
0 Stale
Avg Behind

Dependency List

Latest release v4.0.5

Dependency Type Current Latest Behind CVE License
org.apache.tomcat.embed:tomcat-embed-core
maven
Transitive 10.1.43 12 critical Apache-2.0
org.springframework.security:spring-security-web
maven
Transitive 6.5.2 1 critical Apache-2.0
org.thymeleaf:thymeleaf
maven
Transitive 3.1.3.RELEASE 3 critical Apache-2.0
org.thymeleaf:thymeleaf-spring6
maven
Transitive 3.1.3.RELEASE 3 critical Apache-2.0
io.netty:netty-codec
maven
Transitive 4.1.123.Final 2 high Apache-2.0
org.assertj:assertj-core
maven
Transitive 3.27.3 1 high Apache-2.0
org.postgresql:postgresql
maven
Direct 42.7.7 1 high BSD-2-Clause
org.springframework.boot:spring-boot
maven
Transitive 3.5.4 1 high Apache-2.0
org.springframework.boot:spring-boot-starter-actuator
maven
Direct 3.5.4 2 high Apache-2.0
org.springframework.security:spring-security-core
maven
Transitive 6.5.2 3 high Apache-2.0
org.springframework:spring-core
maven
Transitive 6.2.9 1 high Apache-2.0 AND BSD-3-Clause AND EPL-1.0 AND LicenseRef-scancode-other-copyleft
ch.qos.logback:logback-core
maven
Transitive 1.5.18 2 medium (EPL-1.0 AND LGPL-2.1 AND LGPL-2.1-only) OR (EPL-1.0 AND LGPL-2.1-only)
com.fasterxml.jackson.core:jackson-core
maven
Transitive 2.19.2 1 medium Apache-2.0 AND BSD-2-Clause AND MIT
com.nimbusds:nimbus-jose-jwt
maven
Transitive 9.37.3 1 medium Apache-2.0
org.apache.commons:commons-compress
maven
Transitive 1.24.0 2 medium Apache-2.0 AND LicenseRef-scancode-public-domain AND bzip2-1.0.6
org.springframework.security:spring-security-oauth2-jose
maven
Transitive 6.5.2 1 medium Apache-2.0
org.springframework:spring-webmvc
maven
Transitive 6.2.9 5 medium Apache-2.0 AND BSD-3-Clause AND EPL-1.0 AND LicenseRef-scancode-other-copyleft

License Breakdown

Apache-2.0 98
Unknown 41
MIT 20
Apache-2.0 AND BSD-3-Clause AND EPL-1.0 AND LicenseRef-scancode-other-copyleft 14
LicenseRef-scancode-unknown-license-reference AND EPL-2.0 5
BSD-3-Clause 4
(EPL-1.0 AND LGPL-2.1 AND LGPL-2.1-only) OR (EPL-1.0 AND LGPL-2.1-only) 2
BSD-3-Clause OR EPL-2.0 2
EPL-2.0 OR GPL-2.0-only WITH Classpath-exception-2.0 2
Apache-2.0 AND BSD-2-Clause AND MIT 1
Apache-2.0 AND BSD-3-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND LicenseRef-scancode-public-domain AND bzip2-1.0.6 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND MIT 1
Apache-2.0 OR LGPL-2.1-or-later 1
BSD-2-Clause 1
BSD-2-Clause AND BSD-3-Clause AND CC0-1.0 1
CC0-1.0 1
EPL-1.0 1
EPL-2.0 OR (Apache-2.0 AND EPL-2.0) 1
LicenseRef-scancode-unknown-license-reference AND Apache-2.0 AND EPL-2.0 1
MIT-0 1

CVE Severity

critical 4
high 7
medium 6
low 0
unknown 0

Beta — feedback welcome: [email protected]