Skip to content
Tools / vllm / Dependencies

Dependency Analysis

vllm

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

34% Freshness
1194 Dependencies
537 Outdated
0 Stale
6.6 Avg Behind

Dependency List

Latest release v0.20.1

Dependency Type Current Latest Behind CVE License
chardet
pypi
Direct 5.2.0 7.4.3 13 behind LGPL-2.1-or-later
chardet
pypi
Direct 5.2.0 7.4.3 13 behind LGPL-2.1-or-later
timm
pypi
Direct 1.0.17 1.0.27 10 behind Apache-2.0 AND BSD-3-Clause AND CC-BY-NC-4.0 AND GPL-1.0-or-later AND LGPL-2.0-or-later AND LicenseRef-scancode-proprietary-license AND MIT
timm
pypi
Direct 1.0.17 1.0.27 10 behind Apache-2.0 AND BSD-3-Clause AND CC-BY-NC-4.0 AND GPL-1.0-or-later AND LGPL-2.0-or-later AND LicenseRef-scancode-proprietary-license AND MIT
rapidfuzz
pypi
Direct 3.12.1 3.14.5 7 behind GPL-1.0-or-later AND MIT
rapidfuzz
pypi
Direct 3.12.1 3.14.5 7 behind GPL-1.0-or-later AND MIT
lxml
pypi
Direct 6.0.2 6.1.1 4 behind BSD-3-Clause AND GPL-1.0-or-later
soxr
pypi
Direct 0.5.0.post1 1.1.0 2 behind Python-2.0 AND LGPL-2.1-or-later AND LicenseRef-scancode-other-permissive
soxr
pypi
Direct 0.5.0.post1 1.1.0 2 behind Python-2.0 AND LGPL-2.1-or-later AND LicenseRef-scancode-other-permissive
frozendict
pypi
Direct 2.4.6 2.4.7 1 behind LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later
frozendict
pypi
Direct 2.4.6 2.4.7 1 behind LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later
pycountry
pypi
Direct 24.6.1 26.2.16 1 behind LGPL-2.1-only
pycountry
pypi
Direct 24.6.1 26.2.16 1 behind LGPL-2.1-only
frozendict
pypi
Direct 2.4.7 2.4.7 Current LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later
gitdb
pypi
Direct 4.0.12 4.0.12 Current BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later
html2text
pypi
Direct 2025.4.15 2025.4.15 Current GPL-3.0 AND GPL-3.0-only
html2text
pypi
Direct 2025.4.15 2025.4.15 Current GPL-3.0 AND GPL-3.0-only
num2words
pypi
Direct 0.5.14 0.5.14 Current LGPL-2.1-only AND LGPL-3.0-or-later
num2words
pypi
Direct 0.5.14 0.5.14 Current LGPL-2.1-only AND LGPL-3.0-or-later
pycountry
pypi
Direct 26.2.16 26.2.16 Current LGPL-2.0-only AND LGPL-2.1 AND LGPL-2.1-only
rfc3987
pypi
Direct 1.3.8 1.3.8 Current GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later
rfc3987
pypi
Direct 1.3.8 1.3.8 Current GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later
typing-extensions
pypi
Direct 4.15.0 4.15.0 Current Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD
typing-extensions
pypi
Direct 4.15.0 4.15.0 Current Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD

License Breakdown

Unknown 408
MIT 310
Apache-2.0 157
BSD-2-Clause AND BSD-3-Clause 63
BSD-3-Clause 63
BSD-2-Clause 18
Apache-2.0 AND MIT 13
MPL-2.0 12
LicenseRef-scancode-generic-cla AND MIT 11
ISC 8
BSD-2-Clause AND BSD-3-Clause AND MIT 7
Apache-2.0 AND BSD-2-Clause 6
Unlicense 6
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 5
MIT AND Python-2.0 4
PSF-2.0 4
Apache-2.0 AND BSD-3-Clause AND MIT AND OFL-1.1 3
Apache-2.0 AND BSD-3-Clause AND MPL-2.0 3
Apache-2.0 AND LicenseRef-scancode-generic-cla AND MIT 3
Apache-2.0 AND MIT AND MPL-2.0 3
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain AND Unlicense 3
BSD-2-Clause AND Python-2.0 3
BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 3
CNRI-Python AND Apache-2.0 3
LGPL-3.0 AND LGPL-3.0-only AND LGPL-3.0-or-later 3
MIT AND MPL-2.0 3
0BSD AND BSD-3-Clause AND LicenseRef-scancode-other-permissive AND MIT AND Python-2.0 2
0BSD AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference AND PSF-2.0 AND Python-2.0 2
Apache-2.0 AND BSD-3-Clause 2
Apache-2.0 AND BSD-3-Clause AND CC-BY-NC-4.0 AND GPL-1.0-or-later AND LGPL-2.0-or-later AND LicenseRef-scancode-proprietary-license AND MIT 2
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference 2
Apache-2.0 AND BSD-3-Clause AND MIT AND Zlib 2
BSD-3-Clause AND MIT 2
CC-BY-NC-4.0 2
GPL-1.0-or-later AND MIT 2
GPL-3.0 AND GPL-3.0-only 2
GPL-3.0 AND GPL-3.0-only AND GPL-3.0-or-later 2
LGPL-2.1-only 2
LGPL-2.1-only AND LGPL-3.0-or-later 2
LGPL-2.1-or-later 2
LicenseRef-scancode-proprietary-license AND MIT 2
LicenseRef-scancode-unknown-license-reference AND BSD-3-Clause 2
MIT AND PSF-2.0 AND Python-2.0 2
MIT-0 2
MIT-CMU 2
MPL-2.0 AND MPL-1.1 2
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD 2
Python-2.0 AND LGPL-2.1-or-later AND LicenseRef-scancode-other-permissive 2
(AFL-2.1 AND MIT AND Python-2.0) OR (AFL-2.1 AND MIT) 1
Apache-2.0 AND BSD-3-Clause AND Python-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC0-1.0 AND LicenseRef-scancode-public-domain 1
Apache-2.0 AND LicenseRef-scancode-proprietary-license 1
BSD-2-Clause AND BSD-3-Clause AND BSD-3-Clause-Modification AND HPND AND LicenseRef-scancode-proprietary-license 1
BSD-2-Clause AND BSD-3-Clause AND GPL-1.0-or-later 1
BSD-2-Clause AND BSD-3-Clause AND ISC 1
BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain-disclaimer AND MIT 1
BSD-2-Clause-FreeBSD 1
BSD-3-Clause AND GPL-1.0-or-later 1
BSD-3-Clause AND ISC 1
BSD-3-Clause AND Python-2.0 1
BSD-3-Clause OR Apache-2.0 1
CC0-1.0 AND Unlicense 1
ISC AND MPL-2.0 1
LGPL-2.0-only AND LGPL-2.1 AND LGPL-2.1-only 1
LicenseRef-scancode-public-domain AND Unlicense 1
LicenseRef-scancode-secret-labs-2011 AND MIT-CMU 1
LicenseRef-scancode-us-govt-public-domain AND MIT 1
MIT AND HPND-Markus-Kuhn 1
MIT AND PSF-2.0 1
MIT AND ZPL-2.1 1
PSF-2.0 AND Python-2.0 1

CVE Severity

critical 6
high 25
medium 18
low 2
unknown 2

Beta — feedback welcome: [email protected]