Skip to content
Tools / shardingsphere / Dependencies

Dependency Analysis

shardingsphere

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

100% Freshness
745 Dependencies
0 Outdated
0 Stale
Avg Behind

Dependency List

Latest release 5.5.3

Dependency Type Current Latest Behind CVE License
ch.qos.logback:logback-classic
maven
Direct 1.3.16 (EPL-1.0 AND LGPL-2.1 AND LGPL-2.1-only) OR (EPL-1.0 AND LGPL-2.1-only)
com.h3xstream.findsecbugs:findsecbugs-plugin
maven
Direct 1.12.0 LGPL-3.0-or-later
com.mebigfatguy.fb-contrib:fb-contrib
maven
Direct 7.6.0 Apache-2.0 AND LGPL-2.1-only AND LGPL-3.0
org.mariadb.jdbc:mariadb-java-client
maven
Direct 2.4.2 LGPL-2.1-or-later
org.sonarsource.scanner.maven:sonar-maven-plugin
maven
Direct 3.9.1.2184 LGPL-3.0

License Breakdown

Unknown 674
Apache-2.0 44
MIT 7
BSD-3-Clause 4
BSD-2-Clause 2
MIT AND BSD-3-Clause 2
(EPL-1.0 AND LGPL-2.1 AND LGPL-2.1-only) OR (EPL-1.0 AND LGPL-2.1-only) 1
Apache-2.0 AND BSD-3-Clause 1
Apache-2.0 AND LGPL-2.1-only AND LGPL-3.0 1
Apache-2.0 AND MIT 1
EPL-1.0 OR MPL-2.0 1
EPL-2.0 OR (Apache-2.0 AND EPL-2.0) 1
LGPL-2.1-or-later 1
LGPL-3.0 1
LGPL-3.0-or-later 1
LicenseRef-scancode-oracle-free-2018 1
LicenseRef-scancode-unknown-license-reference AND EPL-2.0 1

CVE Severity

critical 0
high 1
medium 0
low 0
unknown 0

Beta — feedback welcome: [email protected]