Skip to content
Tools / stash / Dependencies

Dependency Analysis

stash

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

60% Freshness
1467 Dependencies
434 Outdated
0 Stale
29.1 Avg Behind

Dependency List

Latest release v0.31.1

Dependency Type Current Latest Behind CVE License
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
braces
npm
Transitive 1.8.5 3.0.3 17 behind 1 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
immutable
npm
Transitive 5.1.4 5.1.6 4 behind 1 high MIT
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
lodash.pick
npm
Transitive 4.4.0 1 high MIT
micromatch
npm
Transitive 2.3.11 4.0.8 26 behind 1 medium MIT
brace-expansion
npm
Transitive 1.1.12 5.0.6 10 behind 1 medium MIT
postcss
npm
Direct 8.5.8 8.5.15 7 behind 1 medium MIT
yaml
npm
Transitive 2.8.1 2.9.0 7 behind 1 medium ISC
js-yaml
npm
Transitive 3.14.1 4.2.0 5 behind 1 medium MIT
diff
npm
Transitive 4.0.2 9.0.0 18 behind 1 low BSD-3-Clause
github.com/disintegration/imaging
golang
Direct v1.6.2 1 low MIT
github.com/go-chi/chi/v5
golang
Direct v5.2.2 1 unknown MIT
golang.org/x/image
golang
Direct v0.38.0 2 unknown Unknown
golang.org/x/net
golang
Direct v0.50.0 2 unknown BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang

License Breakdown

MIT 1203
ISC 62
Apache-2.0 50
BSD-3-Clause 31
BSD-2-Clause 23
Unknown 22
MPL-2.0 17
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 9
Apache-2.0 AND MIT 4
CC0-1.0 4
CC0-1.0 AND MIT 4
(CC-BY-4.0 AND MIT) 3
0BSD 3
MIT OR (CC0-1.0 AND MIT) 3
MIT-0 3
Apache-2.0 AND BSD-2-Clause 2
Apache-2.0 AND BSD-3-Clause AND MIT 2
BSD-3-Clause AND LicenseRef-scancode-facebook-patent-rights-2 2
ISC AND MIT 2
0BSD AND ISC AND MIT 1
0BSD AND MIT 1
AGPL-3.0-or-later 1
Apache-2.0 AND Apache-2.0 WITH LLVM-exception 1
Apache-2.0 OR MIT 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 1
CC-BY-3.0 1
CC-BY-3.0 AND MIT 1
CC-BY-4.0 1
CC0-1.0 OR MIT OR (CC0-1.0 AND MIT) 1
GPL-3.0 1
LGPL-3.0 AND LGPL-3.0-or-later 1
LicenseRef-scancode-dco-1.1 AND MIT 1
MIT AND Zlib 1
Python-2.0 1

CVE Severity

critical 0
high 7
medium 5
low 2
unknown 3

Beta — feedback welcome: [email protected]