Skip to content
Tools / sglang / Dependencies

Dependency Analysis

sglang

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

66% Freshness
231 Dependencies
27 Outdated
0 Stale
4.3 Avg Behind

Dependency List

Latest release v0.5.11

Dependency Type Current Latest Behind CVE License
google.golang.org/grpc
golang
Direct v1.77.0 1 critical Apache-2.0
google.golang.org/grpc
golang
Direct v1.77.0 1 critical Apache-2.0
diffusers
pypi
Direct 0.37.0 0.38.0 2 behind 1 high Unknown
openai
pypi
Direct 2.6.1 2.41.0 38 behind Apache-2.0
outlines
pypi
Direct 0.1.11 1.3.0 28 behind Apache-2.0
checkpoint-engine
pypi
Direct 0.1.2 0.4.0 14 behind MIT
flashinfer-cubin
pypi
Direct 0.6.8.post1 0.6.12 14 behind Unknown
flashinfer-python
pypi
Direct 0.6.8.post1 0.6.12 14 behind Unknown
timm
pypi
Direct 1.0.16 1.0.27 11 behind Apache-2.0 AND BSD-3-Clause AND CC-BY-NC-4.0 AND GPL-1.0-or-later AND LGPL-2.0-or-later AND LicenseRef-scancode-proprietary-license AND MIT
cache-dit
pypi
Direct 1.3.0 1.3.9 9 behind Unknown
openai-protocol
cargo
Direct 1.0.0 1.7.0 8 behind Apache-2.0
transformers
pypi
Direct 5.6.0 5.10.1 8 behind Unknown
reasoning-parser
cargo
Direct 1.0.0 1.2.3 6 behind Apache-2.0
smg-grpc-client
cargo
Direct 1.0.0 1.5.1 6 behind Apache-2.0
smg-mesh
cargo
Direct 1.0.0 1.3.0 6 behind Apache-2.0
data-connector
cargo
Direct 1.0.0 2.2.0 4 behind Apache-2.0
imageio
pypi
Direct 2.36.0 2.37.3 4 behind BSD-2-Clause
nvidia-cutlass-dsl
pypi
Direct 4.4.2 4.5.2 4 behind Unknown
opencv-python-headless
pypi
Direct 4.10.0.84 4.13.0.92 4 behind Apache-2.0 AND MIT
smg-mcp
cargo
Direct 1.0.0 2.2.0 4 behind Apache-2.0
tool-parser
cargo
Direct 1.0.0 1.2.0 4 behind Apache-2.0
pyyaml
pypi
Direct 6.0.1 6.0.3 3 behind MIT
scikit-image
pypi
Direct 0.25.2 0.26.0 3 behind BSD-2-Clause AND BSD-3-Clause AND MIT
sglang-kernel
pypi
Direct 0.4.2 0.4.3 3 behind Unknown
torchcodec
pypi
Direct 0.11.1 0.14.0 3 behind Unknown
wfaas
cargo
Direct 1.0.0 1.0.3 3 behind Apache-2.0
av
pypi
Direct 16.1.0 17.0.1 2 behind Unknown
blobfile
pypi
Direct 3.0.0 3.2.0 2 behind Unlicense
openai-harmony
pypi
Direct 0.0.4 0.0.8 2 behind Apache-2.0
smg-auth
cargo
Direct 1.0.0 1.1.1 2 behind Apache-2.0
smg-wasm
cargo
Direct 1.0.0 1.1.0 2 behind Apache-2.0
imageio-ffmpeg
pypi
Direct 0.5.1 0.6.0 1 behind BSD-2-Clause
st-attn
pypi
Direct 0.0.7 0.0.8 1 behind Unknown
torch
pypi
Direct 2.11.0 2.12.0 1 behind Unknown
vsa
pypi
Direct 0.0.4 0.0.5 1 behind Unknown
xgrammar
pypi
Direct 0.2.0 0.2.1 1 behind Unknown
actions/checkout
githubactions
Direct 4.*.* Unknown
actions/download-artifact
githubactions
Direct 4.*.* Unknown
actions/download-artifact
githubactions
Direct 6.*.* Unknown
actions/github-script
githubactions
Direct 7.*.* Unknown
actions/github-script
githubactions
Direct 6.*.* Unknown
actions/labeler
githubactions
Direct 5.*.* Unknown
actions/setup-python
githubactions
Direct 5.*.* Unknown
actions/setup-python
githubactions
Direct 4.*.* Unknown
actions/upload-artifact
githubactions
Direct 4.*.* Unknown
addict
pypi
Direct 2.4.0 2.4.0 Current MIT
anthropic
Direct Unknown
anyhow
Direct >= 1.0.0,< 2.0.0 Unknown
apache-tvm-ffi
Direct Unknown
aquasecurity/trivy-action
githubactions
Direct 0.35.0 Unknown
arc-swap
Direct >= 1.7.1,< 2.0.0 Unknown
astral-sh/setup-uv
githubactions
Direct 5.*.* Unknown
async-stream
Direct >= 0.3.0,< 0.4.0 Unknown
async-trait
Direct >= 0.1.0,< 0.2.0 Unknown
axum
Direct >= 0.8.6,< 0.9.0 Unknown
axum-server
Direct >= 0.8.0,< 0.9.0 Unknown
base64
Direct >= 0.22.0,< 0.23.0 Unknown
bitflags
Direct >= 2.10.0,< 3.0.0 Unknown
blake3
Direct >= 1.5.0,< 2.0.0 Unknown
bytemuck
Direct >= 1.21.0,< 2.0.0 Unknown
bytes
Direct >= 1.8.0,< 2.0.0 Unknown
chrono
Direct >= 0.4.0,< 0.5.0 Unknown
clap
Direct >= 4.0.0,< 5.0.0 Unknown
cloudpickle
pypi
Direct 3.1.2 3.1.2 Current BSD-3-Clause
crdts
Direct >= 7.3.0,< 8.0.0 Unknown
criterion
Direct >= 0.5.0,< 0.6.0 Unknown
crossbeam-channel
Direct >= 0.5.0,< 0.6.0 Unknown
cuda-python
Direct Unknown
dashmap
Direct >= 6.1.0,< 7.0.0 Unknown
docker/build-push-action
githubactions
Direct 6.*.* Unknown
docker/build-push-action
githubactions
Direct 5.*.* Unknown
docker/login-action
githubactions
Direct 3.*.* Unknown
docker/login-action
githubactions
Direct 2.*.* Unknown
docker/metadata-action
githubactions
Direct 5.*.* Unknown
docker/setup-buildx-action
githubactions
Direct 3.*.* Unknown
docker/setup-qemu-action
githubactions
Direct 3.*.* Unknown
DoozyX/clang-format-lint-action
githubactions
Direct 0.20.* Unknown
dorny/paths-filter
githubactions
Direct 3.*.* Unknown
fastokens
Direct Unknown
flash-attn
Direct >= 2.7.1 Unknown
flash-attn-4
Direct Unknown
futures
Direct >= 0.3.0,< 0.4.0 Unknown
futures-util
Direct >= 0.3.0,< 0.4.0 Unknown
gguf
Direct >= 0.17.1 Unknown
github.com/andybalholm/brotli
golang
Transitive v1.1.0 MIT
github.com/klauspost/compress
golang
Transitive v1.17.9 Apache-2.0 AND BSD-3-Clause AND MIT
github.com/stretchr/testify
golang
Transitive v1.10.0 MIT
github.com/valyala/bytebufferpool
golang
Transitive v1.0.0 MIT
github.com/valyala/fasthttp
golang
Direct v1.52.0 MIT
github/codeql-action/upload-sarif
githubactions
Direct 4.*.* Unknown
go.uber.org/multierr
golang
Transitive v1.10.0 MIT
go.uber.org/zap
golang
Direct v1.27.0 MIT
golang.org/x/net
golang
Transitive v0.46.1-0.20251013234738-63d1a5100f82 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/net
golang
Transitive v0.46.1-0.20251013234738-63d1a5100f82 1 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/sys
golang
Transitive v0.37.0 BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/sys
golang
Transitive v0.37.0 BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/text
golang
Transitive v0.30.0 BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
golang.org/x/text
golang
Transitive v0.30.0 BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
google.golang.org/genproto/googleapis/rpc
golang
Transitive v0.0.0-20251022142026-3a174f9686a8 Apache-2.0
google.golang.org/genproto/googleapis/rpc
golang
Transitive v0.0.0-20251022142026-3a174f9686a8 Apache-2.0
google.golang.org/protobuf
golang
Direct v1.36.10 BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
google.golang.org/protobuf
golang
Transitive v1.36.10 BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
gopkg.in/natefinch/lumberjack.v2
golang
Direct v2.2.1 MIT
granian
Direct Unknown
grpcio
Direct Unknown
grpcio-health-checking
Direct Unknown
http
Direct >= 1.1.0,< 2.0.0 Unknown
http-body
Direct >= 1.0.0,< 2.0.0 Unknown
http-body-util
Direct >= 0.1.0,< 0.2.0 Unknown
httpx
Direct Unknown
ipykernel
Direct Unknown
ipywidgets
Direct Unknown
jlumbroso/free-disk-space
githubactions
Direct main Unknown
jlumbroso/free-disk-space
githubactions
Direct 54081f138730dfa15788a46383842cd2f914a1be Unknown
jsonwebtoken
Direct >= 9.3.0,< 10.0.0 Unknown
jupyter-client
Direct Unknown
k8s-openapi
Direct >= 0.25.0,< 0.26.0 Unknown
kube
Direct >= 1.1.0,< 2.0.0 Unknown
lazy_static
Direct >= 1.4.0,< 2.0.0 Unknown
libc
Direct >= 0.2.179,< 0.3.0 Unknown
llguidance
Direct Unknown
llm-tokenizer
cargo
Direct 1.3.2 1.3.2 Current Apache-2.0
lm-eval
Direct Unknown
lycheeverse/lychee-action
githubactions
Direct 8646ba30535128ac92d33dfc9133794bfdd9b411 Unknown
markdown
Direct >= 3.4.0 Unknown
matplotlib
Direct Unknown
memchr
Direct >= 2.7.0,< 3.0.0 Unknown
metrics
Direct >= 0.24.2,< 0.25.0 Unknown
metrics-exporter-prometheus
Direct >= 0.17.0,< 0.18.0 Unknown
mistral-common
Direct Unknown
moviepy
Direct Unknown
mozilla-actions/sccache-action
githubactions
Direct 0.0.9 Unknown
myst-parser
Direct Unknown
nbconvert
Direct Unknown
nbsphinx
Direct Unknown
nbstripout
Direct Unknown
npyz
Direct >= 0.8.0,< 0.9.0 Unknown
num-bigint
Direct >= 0.4.0,< 0.5.0 Unknown
num-traits
Direct >= 0.2.0,< 0.3.0 Unknown
once_cell
Direct >= 1.21.3,< 2.0.0 Unknown
once_cell
Direct >= 1.19.0,< 2.0.0 Unknown
openai
Direct Unknown
openmetrics-parser
Direct >= 0.4.4,< 0.5.0 Unknown
openssl
Direct >= 0.10.73,< 0.11.0 Unknown
opentelemetry
Direct >= 0.27.0,< 0.28.0 Unknown
opentelemetry-otlp
Direct >= 0.27.0,< 0.28.0 Unknown
opentelemetry-proto
Direct >= 0.27.0,< 0.28.0 Unknown
opentelemetry_sdk
Direct >= 0.27.0,< 0.28.0 Unknown
pandoc
Direct Unknown
parking_lot
Direct >= 0.12.4,< 0.13.0 Unknown
peft
Direct Unknown
pillow
Direct Unknown
portpicker
Direct >= 0.1.0,< 0.2.0 Unknown
prometheus-client
Direct Unknown
prost
Direct >= 0.13.0,< 0.14.0 Unknown
prost
Direct >= 0.14.1,< 0.15.0 Unknown
prost-types
Direct >= 0.14.1,< 0.15.0 Unknown
pydantic
Direct Unknown
pyo3
Direct >= 0.23.0,< 0.24.0 Unknown
pyo3
Direct >= 0.27.1,< 0.28.0 Unknown
PyO3/maturin-action
githubactions
Direct 1.*.* Unknown
pytest
Direct Unknown
pytest-rerunfailures
Direct Unknown
pyzmq
Direct Unknown
quack-kernels
Direct Unknown
rand
Direct >= 0.9.2,< 0.10.0 Unknown
ray
Direct Unknown
redis
Direct >= 0.27.6,< 0.28.0 Unknown
regex
Direct >= 1.10.0,< 2.0.0 Unknown
remote-pdb
pypi
Direct 2.1.0 2.1.0 Current BSD-2-Clause
reqwest
Direct >= 0.12.8,< 0.13.0 Unknown
rmcp
Direct >= 0.8.3,< 0.9.0 Unknown
rsa
Direct >= 0.9.0,< 0.10.0 Unknown
runai-model-streamer
Direct Unknown
rustls
Direct >= 0.23.0,< 0.24.0 Unknown
rustls-pemfile
Direct >= 2.2.0,< 3.0.0 Unknown
scikit-build-core
Direct Unknown
serde
Direct >= 1.0.0,< 2.0.0 Unknown
serde_json
Direct >= 1.0.0,< 2.0.0 Unknown
serde_yaml
Direct >= 0.9.0,< 0.10.0 Unknown
serial_test
Direct >= 3.0.0,< 4.0.0 Unknown
setuptools
Direct Unknown
setuptools-rust
Direct Unknown
setuptools-scm
Direct Unknown
sha2
Direct >= 0.10.0,< 0.11.0 Unknown
smg-grpc-servicer
Direct Unknown
softprops/action-gh-release
githubactions
Direct 2.*.* Unknown
soundfile
pypi
Direct 0.13.1 0.13.1 Current BSD-3-Clause AND Python-2.0
sphinx
Direct Unknown
sphinx-autobuild
Direct Unknown
sphinx-book-theme
Direct Unknown
sphinx-copybutton
Direct Unknown
sphinx-tabs
Direct Unknown
sphinxcontrib-mermaid
Direct Unknown
styfle/cancel-workflow-action
githubactions
Direct 0.12.1 Unknown
subtle
Direct >= 2.6.0,< 3.0.0 Unknown
Swatinem/rust-cache
githubactions
Direct 2.*.* Unknown
tempfile
Direct >= 3.8.0,< 4.0.0 Unknown
thiserror
Direct >= 2.0.12,< 3.0.0 Unknown
tokenizers
Direct >= 0.21.0,< 0.22.0 Unknown
tokio
Direct >= 1.0.0,< 2.0.0 Unknown
tokio
Direct >= 1.42.0,< 2.0.0 Unknown
tokio-stream
Direct >= 0.1.0,< 0.2.0 Unknown
toml
Direct >= 0.9.0,< 0.10.0 Unknown
tonic
Direct >= 0.12.0,< 0.13.0 Unknown
tonic
Direct >= 0.12.3,< 0.13.0 Unknown
tonic
Direct >= 0.14.2,< 0.15.0 Unknown
tonic-build
Direct >= 0.12.0,< 0.13.0 Unknown
tonic-prost
Direct >= 0.14.2,< 0.15.0 Unknown
torch
Direct Unknown
torch-memory-saver
Direct Unknown
torchao
pypi
Direct 0.17.0 0.17.0 Current Unknown
torchaudio
pypi
Direct 2.11.0 2.11.0 Current Unknown
tower
Direct >= 0.5.0,< 0.6.0 Unknown
tower-http
Direct >= 0.6.0,< 0.7.0 Unknown
tracing
Direct >= 0.1.0,< 0.2.0 Unknown
tracing-appender
Direct >= 0.2.3,< 0.3.0 Unknown
tracing-log
Direct >= 0.2.0,< 0.3.0 Unknown
tracing-opentelemetry
Direct >= 0.28.0,< 0.29.0 Unknown
tracing-subscriber
Direct >= 0.3.0,< 0.4.0 Unknown
trimesh
Direct Unknown
url
Direct >= 2.5.4,< 3.0.0 Unknown
urllib3
Direct < 2.0.0 Unknown
uuid
Direct >= 1.0.0,< 2.0.0 Unknown
uuid
Direct >= 1.10.0,< 2.0.0 Unknown
validator
Direct >= 0.20.0,< 0.21.0 Unknown
wasm-encoder
Direct >= 0.242.0,< 0.243.0 Unknown
wasmtime
Direct >= 38.0.0,< 39.0.0 Unknown
wit-bindgen
Direct >= 0.21.0,< 0.22.0 Unknown
xxhash-rust
Direct >= 0.8.0,< 0.9.0 Unknown

License Breakdown

Unknown 184
Apache-2.0 18
MIT 10
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 8
BSD-2-Clause 3
Apache-2.0 AND BSD-3-Clause AND CC-BY-NC-4.0 AND GPL-1.0-or-later AND LGPL-2.0-or-later AND LicenseRef-scancode-proprietary-license AND MIT 1
Apache-2.0 AND BSD-3-Clause AND MIT 1
Apache-2.0 AND MIT 1
BSD-2-Clause AND BSD-3-Clause AND MIT 1
BSD-3-Clause 1
BSD-3-Clause AND Python-2.0 1
Unlicense 1

CVE Severity

critical 2
high 1
medium 0
low 0
unknown 2

Beta — feedback welcome: [email protected]