Skip to content
Tools / trulens / Dependencies

Dependency Analysis

trulens

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

39% Freshness
2340 Dependencies
1088 Outdated
0 Stale
51.5 Avg Behind

Dependency List

Latest release trulens-2.8.0

Dependency Type Current Latest Behind CVE License
h11
pypi
Direct 0.14.0 0.16.0 2 behind 1 critical MIT
llama-index-core
pypi
Direct 0.11.23 0.14.22 98 behind 7 high Unknown
google-cloud-aiplatform
pypi
Direct 1.73.0 1.155.0 87 behind 1 high Apache-2.0
aiohttp
pypi
Direct 3.10.11 3.14.0 49 behind 19 high Apache-2.0
setuptools
pypi
Direct 75.3.0 82.0.1 40 behind 1 high MIT
protobuf
pypi
Direct 5.29.0 7.35.0 39 behind 1 high BSD-3-Clause AND LicenseRef-scancode-protobuf
starlette
pypi
Direct 0.41.3 1.2.1 29 behind 2 high BSD-3-Clause
langchain-text-splitters
pypi
Direct 0.2.2 1.1.2 22 behind 2 high MIT
protobuf
pypi
Transitive 5.29.5 7.35.0 22 behind 1 high BSD-3-Clause AND LicenseRef-scancode-protobuf
orjson
pypi
Direct 3.10.11 3.11.9 17 behind 1 high Apache-2.0 AND MIT
poetry
pypi
Transitive 1.8.4 2.4.1 17 behind 2 high MIT
onnx
pypi
Direct 1.17.0 1.21.0 14 behind 6 high Apache-2.0
llama-index-cli
pypi
Direct 0.3.1 0.5.7 13 behind 1 high MIT
cryptography
pypi
Transitive 46.0.0 48.0.0 9 behind 3 high BSD-3-Clause OR Apache-2.0
simpleeval
pypi
Direct 0.9.13 1.0.7 8 behind 1 high MIT
pillow
pypi
Direct 11.0.0 12.2.0 7 behind 5 high MIT-CMU
axios
npm
Transitive 1.15.1 1.17.0 6 behind 2 high MIT
pyjwt
pypi
Direct 2.9.0 2.13.0 6 behind 1 high MIT
wheel
pypi
Direct 0.45.0 0.47.0 6 behind 1 high MIT
urllib3
pypi
Transitive 2.5.0 2.7.0 5 behind 3 high MIT
jupyter-server
pypi
Transitive 2.17.0 2.19.0 4 behind 4 high BSD-3-Clause
cross-spawn
npm
Transitive 7.0.3 7.0.6 3 behind 1 high MIT
pyopenssl
pypi
Transitive 25.3.0 26.2.0 3 behind 2 high Apache-2.0
mako
pypi
Transitive 1.3.10 1.3.12 2 behind 2 high MIT
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
mistune
pypi
Transitive 3.2.0 3.2.1 1 behind 1 high BSD-3-Clause
langsmith
pypi
Direct 0.1.143 0.8.9 224 behind 1 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
ajv
npm
Transitive 6.12.6 8.20.0 67 behind 1 medium MIT
pypdf
pypi
Direct 4.3.1 6.12.2 44 behind 22 medium BSD-2-Clause AND BSD-3-Clause
filelock
pypi
Direct 3.16.1 3.29.1 23 behind 2 medium Unlicense
marshmallow
pypi
Direct 3.23.1 4.3.0 21 behind 1 medium BSD-3-Clause AND MIT
transformers
pypi
Direct 4.57.6 5.10.1 19 behind 1 medium Apache-2.0
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
pip
pypi
Direct 24.3.1 26.1.2 11 behind 4 medium MIT
postcss
npm
Transitive 8.5.6 8.5.15 9 behind 1 medium MIT
urllib3
pypi
Direct 1.26.20 2.7.0 9 behind 1 medium MIT
pytest
pypi
Direct 8.3.4 9.0.3 8 behind 1 medium MIT
urllib3
pypi
Direct 2.2.3 2.7.0 8 behind 1 medium MIT
requests
pypi
Transitive 2.32.4 2.34.2 7 behind 1 medium Apache-2.0
python-dotenv
pypi
Transitive 1.1.0 1.2.2 4 behind 1 medium BSD-3-Clause
jinja2
pypi
Direct 3.1.4 3.1.6 2 behind 3 medium BSD-2-Clause AND BSD-3-Clause
torch
pypi
Direct 2.7.1 2.12.0 Current 1 medium Unknown
langchain-openai
pypi
Direct 0.1.7 1.2.2 105 behind 1 low MIT
cryptography
pypi
Direct 43.0.3 48.0.0 22 behind 1 low BSD-3-Clause OR Apache-2.0
pygments
pypi
Transitive 2.19.1 2.20.0 2 behind 1 low BSD-2-Clause
py
pypi
Direct 1.11.0 1.11.0 Current 1 unknown MIT

License Breakdown

MIT 1410
Unknown 334
Apache-2.0 178
BSD-3-Clause 90
ISC 66
BSD-2-Clause AND BSD-3-Clause 51
BSD-2-Clause 44
Apache-2.0 AND MIT 28
MPL-2.0 19
Apache-2.0 AND BSD-2-Clause 9
CC0-1.0 AND MIT 7
0BSD 5
BSD-3-Clause AND MIT 5
Unlicense 5
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 3
BSD-3-Clause AND LicenseRef-scancode-protobuf 3
BlueOak-1.0.0 3
CNRI-Python AND Apache-2.0 3
ISC AND MIT 3
MIT AND MPL-2.0 3
MIT-CMU 3
PSF-2.0 3
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 2
0BSD AND ISC AND MIT 2
Apache-2.0 AND MIT AND MPL-2.0 2
Apache-2.0 OR (Apache-2.0 AND MIT) 2
BSD-2-Clause AND BSD-2-Clause-Views 2
BSD-2-Clause AND BSD-3-Clause AND MIT 2
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 2
BSD-3-Clause OR Apache-2.0 2
CC-BY-4.0 2
CC0-1.0 2
LicenseRef-scancode-commercial-license AND LicenseRef-scancode-other-permissive AND MIT 2
MIT AND AFL-3.0 2
MIT AND PSF-2.0 2
MIT AND ZPL-2.1 2
Python-2.0 2
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 2
Python-2.0.1 2
(Apache-2.0 AND BSD-3-Clause AND MIT) OR (Apache-2.0 AND MIT) 1
Apache-2.0 AND BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 1
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 1
Apache-2.0 AND CC-BY-NC-4.0 1
Apache-2.0 AND GPL-1.0-or-later AND LicenseRef-scancode-other-copyleft AND PSF-2.0 AND Python-2.0 1
Apache-2.0 AND GPL-1.0-or-later AND MIT 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND Python-2.0 1
Apache-2.0 OR (Apache-2.0 AND GPL-2.0-only) 1
BSD-2-Clause AND BSD-3-Clause AND CC-PDDC AND GPL-1.0-or-later AND GPL-3.0-only AND GPL-3.0-or-later AND LicenseRef-scancode-free-unknown AND LicenseRef-scancode-other-copyleft AND LicenseRef-scancode-public-domain 1
BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later 1
BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 1
BSD-2-Clause-FreeBSD AND BSD-2-Clause-Views 1
BSD-3-Clause AND CC0-1.0 AND ISC AND MIT 1
CC0-1.0 OR MIT OR (CC0-1.0 AND MIT) 1
GPL-1.0-or-later AND MIT 1
GPL-2.0 1
GPL-3.0-only 1
LicenseRef-scancode-free-unknown AND MIT 1
LicenseRef-scancode-unknown-license-reference AND MIT AND Python-2.0 1
MIT AND CC0-1.0 1
MIT AND HPND-Markus-Kuhn 1
MIT AND LicenseRef-scancode-proprietary-license 1
MIT AND PSF-2.0 AND Python-2.0 1
MIT AND Python-2.0 1
MIT AND Python-2.0 AND MIT 1
MIT AND Python-2.0 AND Python-2.0.1 AND BSD-2-Clause AND MIT AND Python-2.0 AND Python-2.0.1 AND BSD-2-Clause 1
MIT OR WTFPL OR (MIT AND WTFPL) 1
MIT-0 1
PSF-2.0 AND Python-2.0 1

CVE Severity

critical 1
high 25
medium 18
low 3
unknown 1

Beta — feedback welcome: [email protected]