Skip to content
Tools / Vane / Dependencies

Dependency Analysis

Vane

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

63% Freshness
878 Dependencies
273 Outdated
0 Stale
14.1 Avg Behind

Dependency List

Latest release v1.12.2

Dependency Type Current Latest Behind CVE License
protobufjs
npm
Transitive 7.5.4 8.5.0 20 behind 1 critical BSD-3-Clause AND LicenseRef-scancode-protobuf
next
npm
Direct 16.2.2 16.2.7 74 behind 1 high MIT
axios
npm
Direct 1.14.0 1.17.0 9 behind 15 high MIT
@xmldom/xmldom
npm
Transitive 0.8.12 0.9.10 3 behind 4 high MIT
esbuild
npm
Transitive 0.15.18 0.28.0 109 behind 1 medium MIT
postcss
npm
Transitive 8.4.31 8.5.15 34 behind 1 medium MIT
dompurify
npm
Transitive 3.3.3 3.4.8 9 behind 4 medium (Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0)
follow-redirects
npm
Transitive 1.15.11 1.16.0 1 behind 1 medium MIT

License Breakdown

MIT 685
Apache-2.0 57
ISC 45
BSD-3-Clause 23
BSD-2-Clause 14
BSD-2-Clause AND LGPL-2.0-only AND LGPL-2.1-only AND LGPL-3.0-only AND LGPL-3.0-or-later AND LicenseRef-scancode-other-permissive AND MIT AND MPL-2.0 10
BlueOak-1.0.0 7
Unknown 4
Apache-2.0 AND BSD-2-Clause AND LGPL-2.0-only AND LGPL-2.1-only AND LGPL-3.0-only AND LGPL-3.0-or-later AND LicenseRef-scancode-other-permissive AND MIT AND MPL-2.0 3
CC0-1.0 3
Apache-2.0 AND BSD-2-Clause 2
MIT AND Zlib 2
MIT-0 2
(Apache-2.0 AND GPL-1.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-1.0-only AND MPL-2.0) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0 AND MS-PL) OR (Apache-2.0 AND GPL-2.0-only AND MPL-2.0) 1
0BSD 1
0BSD AND MIT 1
AFL-2.1 AND AFL-3.0 AND BSD-3-Clause 1
Apache-2.0 AND MIT 1
Apache-2.0 OR BSD-2-Clause OR MIT OR (Apache-2.0 AND BSD-2-Clause) OR (Apache-2.0 AND MIT) OR (BSD-2-Clause AND MIT) 1
BSD-2-Clause AND BSD-2-Clause-Views 1
BSD-3-Clause AND LicenseRef-scancode-protobuf 1
CC-BY-3.0 AND CC-BY-SA-3.0 AND MIT 1
CC-BY-4.0 1
CC0-1.0 AND MIT 1
GPL-3.0-only OR MIT 1
ISC AND MIT 1
LicenseRef-scancode-unknown-license-reference AND MIT 1
MIT AND Ruby 1
MIT OR (CC0-1.0 AND MIT) 1
MIT OR (MIT AND WTFPL) 1
MPL-2.0 1
PSF-2.0 1
Python-2.0 1

CVE Severity

critical 1
high 3
medium 4
low 0
unknown 0

Beta — feedback welcome: [email protected]