Skip to content
Tools / Trivy / Dependencies

Dependency Analysis

Trivy

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

100% Freshness
514 Dependencies
0 Outdated
0 Stale
Avg Behind

Dependency List

Latest release v0.70.0

Dependency Type Current Latest Behind CVE License
github.com/spdx/tools-golang
golang
Direct v0.5.7 Apache-2.0 AND CC-BY-4.0 AND GPL-2.0
github.com/theupdateframework/go-tuf/v2
golang
Transitive v2.4.1 Apache-2.0 OR (Apache-2.0 AND GPL-2.0-only)

License Breakdown

Apache-2.0 165
MIT 130
Unknown 82
BSD-3-Clause 48
Apache-2.0 AND BSD-3-Clause 17
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 14
MPL-2.0 13
BSD-2-Clause 9
Apache-2.0 AND MIT 5
LicenseRef-scancode-generic-cla AND MIT 5
Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause 2
Apache-2.0 AND BSD-3-Clause AND MIT 2
ISC 2
Unlicense 2
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC-BY-4.0 AND GPL-2.0 1
Apache-2.0 AND CC-BY-SA-4.0 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference AND MIT 1
Apache-2.0 OR (Apache-2.0 AND GPL-2.0-only) 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-2-Clause AND ISC 1
BSD-2-Clause-Views 1
BSD-3-Clause AND CC-BY-4.0 AND LicenseRef-scancode-google-patent-license-golang 1
BSD-3-Clause AND MIT 1
BSD-3-Clause AND MPL-2.0 1
LicenseRef-scancode-dco-1.1 AND LicenseRef-scancode-generic-cla AND MIT 1
LicenseRef-scancode-public-domain-disclaimer 1
LicenseRef-scancode-unknown-license-reference AND MIT 1
MIT-0 1

CVE Severity

critical 0
high 1
medium 0
low 0
unknown 1

Beta — feedback welcome: [email protected]