Skip to content
Tools / Upsonic / Dependencies

Dependency Analysis

Upsonic

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

46% Freshness
408 Dependencies
174 Outdated
0 Stale
4.6 Avg Behind

Dependency List

Latest release 0.76.2

Dependency Type Current Latest Behind CVE License
fastmcp
pypi
Direct 2.14.5 3.4.0 22 behind 3 critical Apache-2.0
authlib
pypi
Transitive 1.6.6 1.7.2 9 behind 5 critical BSD-3-Clause
nltk
pypi
Transitive 3.9.2 3.9.4 2 behind 7 critical Apache-2.0
protobuf
pypi
Direct 5.29.5 7.35.0 22 behind 1 high BSD-3-Clause AND LicenseRef-scancode-protobuf
curl-cffi
pypi
Transitive 0.13.0 0.15.0 14 behind 1 high BSD-3-Clause AND MIT
python-multipart
pypi
Direct 0.0.21 0.0.30 9 behind 3 high Apache-2.0
azure-core
pypi
Direct 1.37.0 1.41.0 7 behind 1 high LicenseRef-scancode-generic-cla AND MIT
cryptography
pypi
Transitive 46.0.3 48.0.0 6 behind 3 high BSD-3-Clause OR Apache-2.0
lxml
pypi
Direct 6.0.2 6.1.1 4 behind 1 high BSD-3-Clause AND GPL-1.0-or-later
orjson
pypi
Transitive 3.11.5 3.11.9 4 behind 1 high Apache-2.0 AND MIT
pillow
pypi
Direct 11.3.0 12.2.0 4 behind 6 high LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
pyjwt
pypi
Transitive 2.10.1 2.13.0 4 behind 1 high MIT
pyasn1
pypi
Transitive 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
urllib3
pypi
Transitive 2.6.2 2.7.0 2 behind 1 high MIT
lupa
pypi
Direct 2.6 2.8.0 1 high MIT
transformers
pypi
Direct 4.57.3 5.10.1 26 behind 1 medium Apache-2.0
pypdf
pypi
Direct 6.5.0 6.12.2 20 behind 18 medium BSD-3-Clause
virtualenv
pypi
Transitive 20.35.4 21.4.2 19 behind 1 medium MIT
filelock
pypi
Transitive 3.20.2 3.29.1 17 behind 1 medium Unlicense
requests
pypi
Direct 2.32.5 2.34.2 6 behind 1 medium Apache-2.0
aiohttp
pypi
Direct 3.13.3 3.14.0 3 behind 10 medium Apache-2.0 AND MIT
pytest
pypi
Direct 9.0.2 9.0.3 1 behind 1 medium MIT
python-dotenv
pypi
Direct 1.2.1 1.2.2 1 behind 1 medium BSD-3-Clause
diskcache
pypi
Transitive 5.6.3 5.6.3 Current 1 medium Apache-2.0
uv
pypi
Direct 0.9.22 0.11.19 41 behind 1 low Unknown
mem0ai
pypi
Direct 1.0.1 2.0.4 18 behind 1 low Apache-2.0
pygments
pypi
Transitive 2.19.2 2.20.0 1 behind 1 low BSD-2-Clause

License Breakdown

MIT 135
Apache-2.0 79
Unknown 69
BSD-3-Clause 33
BSD-2-Clause AND BSD-3-Clause 15
BSD-2-Clause 11
Apache-2.0 AND MIT 10
ISC 3
MIT AND Python-2.0 3
Apache-2.0 AND BSD-2-Clause 2
BSD-2-Clause AND BSD-3-Clause AND MIT 2
LicenseRef-scancode-generic-cla AND MIT 2
MPL-2.0 2
(Apache-2.0 AND BSD-3-Clause AND LicenseRef-PdfiumThirdParty) OR (Apache-2.0 AND LicenseRef-PdfiumThirdParty) OR (BSD-3-Clause AND LicenseRef-PdfiumThirdParty) 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0 1
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 1
AGPL-3.0 AND AGPL-3.0-only AND AGPL-3.0-or-later 1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1 1
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 1
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 1
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC-BY-NC-4.0 AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND LicenseRef-scancode-other-permissive 1
Apache-2.0 OR BSD-3-Clause OR (Apache-2.0 AND BSD-3-Clause) 1
BSD-2-Clause AND BSD-3-Clause AND CC-PDDC AND GPL-1.0-or-later AND GPL-3.0-only AND GPL-3.0-or-later AND LicenseRef-scancode-free-unknown AND LicenseRef-scancode-other-copyleft AND LicenseRef-scancode-public-domain 1
BSD-2-Clause AND BSD-3-Clause AND ISC AND Python-2.0 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
BSD-2-Clause AND MIT AND Python-2.0 AND Python-2.0.1 1
BSD-3-Clause AND CC-BY-SA-4.0 1
BSD-3-Clause AND GPL-1.0-or-later 1
BSD-3-Clause AND LGPL-2.1-only 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 1
BSD-3-Clause AND MIT 1
BSD-3-Clause OR Apache-2.0 1
BSL-1.0 AND MIT 1
BUSL-1.1 AND MIT 1
CC0-1.0 AND Unlicense 1
CNRI-Python AND Apache-2.0 1
ISC AND MPL-2.0 1
LGPL-2.0-or-later AND LGPL-3.0-or-later 1
LGPL-3.0 AND LGPL-3.0-only 1
LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 1
LicenseRef-scancode-free-unknown AND MIT 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
MIT AND PSF-2.0 AND Python-2.0 1
MIT AND ZPL-2.1 1
MIT-0 1
OLDAP-2.8 1
PSF-2.0 1
PSF-2.0 AND Python-2.0 1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 1
Unlicense 1

CVE Severity

critical 3
high 12
medium 9
low 3
unknown 0

Beta — feedback welcome: [email protected]