Skip to content
Tools / sandbox / Dependencies

Dependency Analysis

sandbox

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

40% Freshness
958 Dependencies
489 Outdated
0 Stale
17.3 Avg Behind

Dependency List

Latest release v1.0.0.152

Dependency Type Current Latest Behind CVE License
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
langchain-core
pypi
Direct 1.2.19 1.4.0 25 behind 2 high Unknown
rollup
npm
Transitive 4.53.3 4.61.0 21 behind 1 high 0BSD AND ISC AND MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
urllib3
pypi
Direct 2.2.3 2.7.0 8 behind 5 high MIT
@remix-run/router
npm
Transitive 1.23.0 1.23.3 7 behind 1 high MIT
flatted
npm
Transitive 3.3.3 3.4.2 4 behind 2 high ISC
immutable
npm
Transitive 5.1.4 5.1.6 4 behind 1 high MIT
lodash-es
npm
Transitive 4.17.21 4.18.1 4 behind 3 high CC0-1.0 AND MIT
defu
npm
Transitive 6.1.4 6.1.7 3 behind 1 high MIT
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
pyasn1
pypi
Direct 0.6.2 0.6.3 1 behind 1 high BSD-2-Clause AND BSD-3-Clause AND MIT
react-router
npm
Transitive 6.30.1 7.16.0 338 behind 1 medium MIT
langsmith
pypi
Direct 0.4.37 0.8.9 91 behind 2 medium MIT
unhead
npm
Transitive 1.11.20 3.1.1 82 behind 3 medium MIT
vite
npm
Transitive 5.4.21 8.0.16 51 behind 1 medium Apache-2.0 AND BSD-2-Clause AND BlueOak-1.0.0 AND CC0-1.0 AND ISC AND MIT
esbuild
npm
Transitive 0.21.5 0.28.0 28 behind 1 medium MIT
langgraph-checkpoint
pypi
Direct 3.0.0 4.1.1 14 behind 1 medium MIT
brace-expansion
npm
Transitive 2.0.2 5.0.6 11 behind 1 medium MIT
postcss
npm
Transitive 8.5.6 8.5.15 9 behind 1 medium MIT
yaml
npm
Transitive 2.8.0 2.9.0 8 behind 1 medium ISC
requests
pypi
Direct 2.32.5 2.34.2 6 behind 1 medium Apache-2.0
js-yaml
npm
Transitive 3.14.1 4.2.0 5 behind 1 medium MIT
ajv
npm
Transitive 8.17.1 8.20.0 4 behind 1 medium MIT
cryptography
pypi
Direct 46.0.5 48.0.0 4 behind 2 medium Apache-2.0 AND BSD-3-Clause
python-dotenv
pypi
Direct 1.1.1 1.2.2 3 behind 1 medium BSD-3-Clause
mdast-util-to-hast
npm
Transitive 13.2.0 13.2.1 1 behind 1 medium MIT
diskcache
pypi
Direct 5.6.3 5.6.3 Current 1 medium Apache-2.0
langchain-openai
pypi
Direct 1.0.1 1.2.2 22 behind 1 low MIT

License Breakdown

MIT 764
Unknown 49
ISC 33
Apache-2.0 26
BSD-3-Clause 20
BSD-2-Clause 9
Apache-2.0 OR MIT OR (Apache-2.0 AND MIT) 8
BSD-2-Clause AND BSD-3-Clause 5
Apache-2.0 AND MIT 4
BlueOak-1.0.0 4
MPL-2.0 4
CC0-1.0 3
Apache-2.0 AND BSD-2-Clause 2
Apache-2.0 AND BSD-3-Clause 2
CNRI-Python AND Apache-2.0 2
ISC AND MIT 2
(MIT OR CC0-1.0) 1
0BSD 1
0BSD AND ISC AND MIT 1
0BSD AND MIT 1
Apache-2.0 AND BSD-2-Clause AND BlueOak-1.0.0 AND CC0-1.0 AND ISC AND MIT 1
Apache-2.0 AND BSD-3-Clause AND ISC AND MIT 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MIT 1
Apache-2.0 AND MIT AND MPL-2.0 1
BSD-2-Clause AND BSD-3-Clause AND MIT 1
BSD-3-Clause AND MIT 1
CC-BY-4.0 1
CC0-1.0 AND MIT 1
MIT AND MPL-2.0 1
MIT AND Python-2.0 1
MIT-0 1
PSF-2.0 1
Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Python-2.0.1 1

CVE Severity

critical 0
high 12
medium 16
low 1
unknown 0

Beta — feedback welcome: [email protected]