Skip to content
Tools / RSSBox / Dependencies

Dependency Analysis

RSSBox

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

84% Freshness
89 Dependencies
6 Outdated
0 Stale
0.7 Avg Behind

Dependency List

Latest release 2026.4.11

Dependency Type Current Latest Behind CVE License
mistune
pypi
Direct 3.2.0 3.2.1 1 behind 1 high BSD-3-Clause
lxml
pypi
Direct 6.0.3 1 high Unknown

License Breakdown

Unknown 31
MIT 22
BSD-3-Clause 9
Apache-2.0 5
BSD-2-Clause AND BSD-3-Clause 3
BSD-2-Clause 2
(Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND MIT) OR (BSD-2-Clause AND BSD-3-Clause AND GPL-2.0-only AND MIT) 1
Apache-2.0 AND BSD-2-Clause 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND MIT 1
BSD-2-Clause AND LGPL-3.0-only 1
BSD-2-Clause AND LicenseRef-scancode-other-permissive 1
BSD-3-Clause OR Apache-2.0 1
CNRI-Python AND Apache-2.0 1
GPL-3.0 AND GPL-3.0-only 1
GPL-3.0-or-later AND LGPL-2.0-or-later AND LGPL-2.1-or-later AND LGPL-3.0-only 1
MIT AND HPND 1
MIT AND MPL-2.0 1
MIT-0 1
MIT-CMU 1
MPL-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1

CVE Severity

critical 0
high 2
medium 0
low 0
unknown 0

Beta — feedback welcome: [email protected]