Skip to content
Tools / romm / Dependencies

Dependency Analysis

romm

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

57% Freshness
922 Dependencies
312 Outdated
0 Stale
5.7 Avg Behind

Dependency List

Latest release 4.8.1

Dependency Type Current Latest Behind CVE License
axios
npm
Direct 1.15.0 1.17.0 8 behind 13 high MIT
python-multipart
pypi
Direct 0.0.22 0.0.30 8 behind 2 high Apache-2.0
serialize-javascript
npm
Transitive 6.0.2 7.0.5 6 behind 2 high BSD-3-Clause
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
mako
pypi
Transitive 1.3.11 1.3.12 1 behind 1 high MIT
authlib
pypi
Direct 1.6.9 1.7.2 6 behind 1 medium BSD-3-Clause
requests
pypi
Transitive 2.32.5 2.34.2 6 behind 1 medium Apache-2.0
cryptography
pypi
Transitive 46.0.5 48.0.0 4 behind 2 medium Apache-2.0 AND BSD-3-Clause
aiohttp
pypi
Direct 3.13.3 3.14.0 3 behind 10 medium Apache-2.0 AND MIT
pygments
pypi
Transitive 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause

License Breakdown

MIT 677
Apache-2.0 57
ISC 33
Unknown 33
BSD-3-Clause 23
BSD-2-Clause 16
BSD-2-Clause AND BSD-3-Clause 15
MPL-2.0 15
BlueOak-1.0.0 8
Apache-2.0 AND MIT 7
BSD-2-Clause AND MIT AND Python-2.0 AND Python-2.0.1 2
LicenseRef-scancode-unicode AND MIT 2
PSF-2.0 2
Unlicense 2
0BSD 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
0BSD AND ISC AND MIT 1
AFL-2.1 AND AFL-3.0 AND BSD-3-Clause 1
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 1
Apache-2.0 AND BSD-3-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
BSD-3-Clause AND MIT 1
CC-BY-3.0 AND MIT 1
CC-BY-4.0 1
CC0-1.0 AND MIT 1
EPL-2.0 OR (EPL-2.0 AND GPL-2.0-or-later) 1
GPL-1.0-or-later AND GPL-2.0 AND GPL-2.0-or-later AND GPL-3.0-or-later 1
GPL-1.0-or-later AND GPL-2.0-only 1
ISC AND MIT 1
JSON AND MIT 1
LGPL-2.0-or-later AND LGPL-2.1 AND LGPL-2.1-only AND LGPL-2.1-or-later AND Python-2.0 1
LGPL-2.0-or-later AND LGPL-2.1-only AND LGPL-3.0-only 1
LGPL-2.1-only AND LGPL-2.1-or-later 1
LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 1
LGPL-3.0-only AND LGPL-3.0-or-later 1
MIT AND PSF-2.0 AND Python-2.0 1
MIT OR (CC0-1.0 AND MIT) 1
MIT-CMU 1
Python-2.0 1
Python-2.0.1 1

CVE Severity

critical 0
high 5
medium 4
low 1
unknown 0

Beta — feedback welcome: [email protected]