Skip to content
Tools / vllm / Dependencies

Dependency Analysis

vllm

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

34% Freshness
1194 Dependencies
537 Outdated
0 Stale
6.6 Avg Behind

Dependency List

Latest release v0.20.1

Dependency Type Current Latest Behind CVE License
ray
pypi
Direct 2.48.0 2.55.1 17 behind 4 critical Unknown
ray
pypi
Direct 2.48.0 2.55.1 17 behind 4 critical Unknown
nltk
pypi
Direct 3.9.1 3.9.4 3 behind 7 critical Apache-2.0
nltk
pypi
Direct 3.9.1 3.9.4 3 behind 7 critical Apache-2.0
h11
pypi
Direct 0.14.0 0.16.0 2 behind 1 critical MIT
h11
pypi
Direct 0.14.0 0.16.0 2 behind 1 critical MIT
setuptools
pypi
Direct 77.0.3 82.0.1 25 behind 1 high MIT
setuptools
pypi
Direct 77.0.3 82.0.1 25 behind 1 high MIT
black
pypi
Direct 24.10.0 26.5.1 10 behind 1 high MIT
black
pypi
Direct 24.10.0 26.5.1 10 behind 1 high MIT
lxml
pypi
Direct 5.3.0 6.1.1 10 behind 1 high BSD-2-Clause AND BSD-3-Clause
lxml
pypi
Direct 5.3.0 6.1.1 10 behind 1 high BSD-2-Clause AND BSD-3-Clause
cryptography
pypi
Direct 46.0.0 48.0.0 9 behind 1 high BSD-3-Clause OR Apache-2.0
pillow
pypi
Direct 10.4.0 12.2.0 8 behind 5 high MIT-CMU
pillow
pypi
Direct 10.4.0 12.2.0 8 behind 5 high MIT-CMU
urllib3
pypi
Direct 2.2.3 2.7.0 8 behind 5 high MIT
urllib3
pypi
Direct 2.2.3 2.7.0 8 behind 5 high MIT
gitpython
pypi
Direct 3.1.44 3.1.50 6 behind 4 high BSD-3-Clause
geopandas
pypi
Direct 1.0.1 1.1.3 4 behind 1 high BSD-2-Clause AND BSD-3-Clause
orjson
pypi
Direct 3.11.5 3.11.9 4 behind 1 high Apache-2.0 AND MIT
orjson
pypi
Direct 3.11.5 3.11.9 4 behind 1 high Apache-2.0 AND MIT
python-multipart
pypi
Direct 0.0.26 0.0.30 4 behind 1 high Unknown
diffusers
pypi
Direct 0.36.0 0.38.0 3 behind 1 high Apache-2.0
pyjwt
pypi
Direct 2.11.0 2.13.0 3 behind 1 high MIT
pyjwt
pypi
Direct 2.11.0 2.13.0 3 behind 1 high MIT
mako
pypi
Direct 1.3.10 1.3.12 2 behind 2 high MIT
mako
pypi
Direct 1.3.10 1.3.12 2 behind 2 high MIT
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
pyasn1
pypi
Direct 0.6.1 0.6.3 2 behind 2 high BSD-2-Clause
sqlitedict
pypi
Direct 2.1.0 2.1.0 Current 1 high Apache-2.0
sqlitedict
pypi
Direct 2.1.0 2.1.0 Current 1 high Apache-2.0
virtualenv
pypi
Direct 20.31.2 21.4.2 28 behind 1 medium MIT
virtualenv
pypi
Direct 20.31.2 21.4.2 28 behind 1 medium MIT
fonttools
pypi
Direct 4.55.0 4.63.0 27 behind 1 medium Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1
fonttools
pypi
Direct 4.55.0 4.63.0 27 behind 1 medium Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1
filelock
pypi
Direct 3.16.1 3.29.1 23 behind 2 medium Unlicense
filelock
pypi
Direct 3.16.1 3.29.1 23 behind 2 medium Unlicense
requests
pypi
Direct 2.32.3 2.34.2 8 behind 2 medium Apache-2.0
requests
pypi
Direct 2.32.3 2.34.2 8 behind 2 medium Apache-2.0
pytest
pypi
Direct 8.3.5 9.0.3 7 behind 1 medium MIT
pytest
pypi
Direct 8.3.5 9.0.3 7 behind 1 medium MIT
werkzeug
pypi
Direct 3.1.3 3.1.8 5 behind 3 medium BSD-2-Clause AND BSD-3-Clause
werkzeug
pypi
Direct 3.1.3 3.1.8 5 behind 3 medium BSD-2-Clause AND BSD-3-Clause
cryptography
pypi
Direct 46.0.5 48.0.0 4 behind 2 medium Apache-2.0 AND BSD-3-Clause
cryptography
pypi
Direct 46.0.5 48.0.0 4 behind 2 medium Apache-2.0 AND BSD-3-Clause
aiohttp
pypi
Direct 3.13.3 3.14.0 3 behind 10 medium Apache-2.0 AND MIT
aiohttp
pypi
Direct 3.13.3 3.14.0 3 behind 10 medium Apache-2.0 AND MIT
pillow
pypi
Direct 12.1.1 12.2.0 1 behind 1 medium LicenseRef-scancode-secret-labs-2011 AND MIT-CMU
diskcache
pypi
Direct 5.6.3 5.6.3 Current 1 medium Apache-2.0
pygments
pypi
Direct 2.18.0 2.20.0 4 behind 1 low BSD-2-Clause
pygments
pypi
Direct 2.18.0 2.20.0 4 behind 1 low BSD-2-Clause
py
pypi
Direct 1.11.0 1.11.0 Current 1 unknown MIT
py
pypi
Direct 1.11.0 1.11.0 Current 1 unknown MIT

License Breakdown

Unknown 408
MIT 310
Apache-2.0 157
BSD-2-Clause AND BSD-3-Clause 63
BSD-3-Clause 63
BSD-2-Clause 18
Apache-2.0 AND MIT 13
MPL-2.0 12
LicenseRef-scancode-generic-cla AND MIT 11
ISC 8
BSD-2-Clause AND BSD-3-Clause AND MIT 7
Apache-2.0 AND BSD-2-Clause 6
Unlicense 6
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 5
MIT AND Python-2.0 4
PSF-2.0 4
Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1 3
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 3
Apache-2.0 AND LicenseRef-scancode-generic-cla AND MIT 3
Apache-2.0 AND MIT AND MPL-2.0 3
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain AND Unlicense 3
BSD-2-Clause AND Python-2.0 3
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 3
CNRI-Python AND Apache-2.0 3
LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 3
MIT AND MPL-2.0 3
0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0 2
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 2
Apache-2.0 AND BSD-3-Clause 2
Apache-2.0 AND BSD-3-Clause AND CC-BY-NC-4.0 AND GPL-1.0-or-later AND LGPL-2.0-or-later AND LicenseRef-scancode-proprietary-license AND MIT 2
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 2
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 2
BSD-3-Clause AND MIT 2
CC-BY-NC-4.0 2
GPL-1.0-or-later AND MIT 2
GPL-3.0 AND GPL-3.0-only 2
GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later 2
LGPL-2.1-only 2
LGPL-2.1-only AND LGPL-3.0-or-later 2
LGPL-2.1-or-later 2
LicenseRef-scancode-proprietary-license AND MIT 2
LicenseRef-scancode-unknown-license-reference AND BSD-3-Clause 2
MIT AND PSF-2.0 AND Python-2.0 2
MIT-0 2
MIT-CMU 2
MPL-2.0 AND MPL-1.1 2
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 2
Python-2.0 AND LGPL-2.1-or-later AND LicenseRef-scancode-other-permissive 2
(AFL-2.1 AND MIT AND Python-2.0) OR (AFL-2.1 AND MIT) 1
Apache-2.0 AND BSD-3-Clause AND Python-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC0-1.0 AND LicenseRef-scancode-public-domain 1
Apache-2.0 AND LicenseRef-scancode-proprietary-license 1
BSD-2-Clause AND BSD-3-Clause AND BSD-3-Clause-Modification AND HPND AND LicenseRef-scancode-proprietary-license 1
BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later 1
BSD-2-Clause AND BSD-3-Clause AND ISC 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain-disclaimer AND MIT 1
BSD-2-Clause-FreeBSD 1
BSD-3-Clause AND GPL-1.0-or-later 1
BSD-3-Clause AND ISC 1
BSD-3-Clause AND Python-2.0 1
BSD-3-Clause OR Apache-2.0 1
CC0-1.0 AND Unlicense 1
ISC AND MPL-2.0 1
LGPL-2.0-only AND LGPL-2.1 AND LGPL-2.1-only 1
LicenseRef-scancode-public-domain AND Unlicense 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
LicenseRef-scancode-us-govt-public-domain AND MIT 1
MIT AND HPND-Markus-Kuhn 1
MIT AND PSF-2.0 1
MIT AND ZPL-2.1 1
PSF-2.0 AND Python-2.0 1

CVE Severity

critical 6
high 25
medium 18
low 2
unknown 2

Beta — feedback welcome: [email protected]