Dependency Analysis
werf
Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.
81%
Freshness
742
Dependencies
112
Outdated
0
Stale
30.3
Avg Behind
Dependency List
Latest release v2.67.2
| Dependency | Type | Current | Latest | Behind | CVE | License |
|---|---|---|---|---|---|---|
|
minimatch
npm
|
Transitive | 3.1.2 | 10.2.5 | 91 behind | 3 high | ISC |
|
semver
npm
|
Transitive | 6.3.0 | 7.8.1 | 38 behind | 1 high | ISC |
|
picomatch
npm
|
Transitive | 2.3.1 | 4.0.4 | 9 behind | 2 high | MIT |
|
cross-spawn
npm
|
Transitive | 7.0.3 | 7.0.6 | 3 behind | 1 high | MIT |
|
braces
npm
|
Transitive | 3.0.2 | 3.0.3 | 1 behind | 1 high | MIT |
|
@babel/runtime
npm
|
Transitive | 7.18.9 | 7.29.7 | 87 behind | 1 medium | MIT |
|
ajv
npm
|
Transitive | 6.12.6 | 8.20.0 | 67 behind | 1 medium | MIT |
|
brace-expansion
npm
|
Transitive | 1.1.11 | 5.0.6 | 18 behind | 2 medium | MIT |
|
js-yaml
npm
|
Transitive | 4.1.0 | 4.2.0 | 3 behind | 1 medium | MIT |
|
micromatch
npm
|
Transitive | 4.0.5 | 4.0.8 | 3 behind | 1 medium | MIT |
|
react-is
npm
|
Transitive | 16.13.1 | 19.2.7 | 2545 behind | — | MIT |
|
eslint-plugin-react-hooks
npm
|
Direct | 4.6.0 | 7.1.1 | 1857 behind | — | MIT |
|
type-fest
npm
|
Transitive | 0.20.2 | 5.7.0 | 160 behind | — | CC0-1.0 AND MIT |
|
eslint
npm
|
Direct | 8.22.0 | 10.4.1 | 110 behind | — | MIT |
|
glob
npm
|
Transitive | 7.2.3 | 13.0.6 | 62 behind | — | ISC |
|
globals
npm
|
Transitive | 13.17.0 | 17.6.0 | 37 behind | — | MIT |
|
whatwg-url
npm
|
Transitive | 5.0.0 | 16.0.1 | 36 behind | — | MIT |
|
rimraf
npm
|
Transitive | 3.0.2 | 6.1.3 | 35 behind | — | ISC |
|
file-entry-cache
npm
|
Transitive | 6.0.1 | 11.1.3 | 29 behind | — | MIT |
|
flat-cache
npm
|
Transitive | 3.0.4 | 6.1.22 | 28 behind | — | MIT |
|
debug
npm
|
Transitive | 2.6.9 | 4.4.3 | 25 behind | — | MIT |
|
node-fetch
npm
|
Transitive | 2.6.7 | 3.3.2 | 24 behind | — | MIT |
|
globby
npm
|
Transitive | 11.1.0 | 16.2.0 | 20 behind | — | MIT |
|
supports-color
npm
|
Transitive | 7.2.0 | 10.2.2 | 18 behind | — | MIT |
|
ignore
npm
|
Transitive | 5.2.0 | 7.0.5 | 16 behind | — | MIT |
|
uuid
npm
|
Transitive | 8.3.2 | 14.0.0 | 15 behind | — | MIT |
|
eslint-scope
npm
|
Transitive | 7.1.1 | 9.1.2 | 14 behind | — | BSD-2-Clause |
|
eslint-visitor-keys
npm
|
Transitive | 2.1.0 | 5.0.1 | 14 behind | — | Apache-2.0 |
|
resolve
npm
|
Transitive | 1.22.1 | 1.22.12 | 14 behind | — | MIT |
|
tr46
npm
|
Transitive | 0.0.3 | 6.0.0 | 14 behind | — | MIT |
|
eslint-plugin-import
npm
|
Direct | 2.26.0 | 2.32.0 | 13 behind | — | MIT |
|
resolve
npm
|
Transitive | 2.0.0-next.4 | 1.22.12 | 13 behind | — | MIT |
|
chalk
npm
|
Transitive | 4.1.2 | 5.6.2 | 12 behind | — | MIT |
|
is-core-module
npm
|
Transitive | 2.10.0 | 2.16.2 | 11 behind | — | MIT |
|
eslint-module-utils
npm
|
Transitive | 2.7.4 | 2.13.0 | 10 behind | — | MIT |
|
eslint-visitor-keys
npm
|
Transitive | 3.3.0 | 5.0.1 | 10 behind | — | Apache-2.0 |
|
fastq
npm
|
Transitive | 1.13.0 | 1.20.1 | 10 behind | — | ISC |
|
js-tokens
npm
|
Transitive | 4.0.0 | 10.0.0 | 10 behind | — | MIT |
|
p-limit
npm
|
Transitive | 3.1.0 | 7.3.0 | 10 behind | — | MIT |
|
@octokit/openapi-types
npm
|
Transitive | 22.2.0 | 27.0.0 | 9 behind | — | MIT |
|
ansi-styles
npm
|
Transitive | 4.3.0 | 6.2.3 | 9 behind | — | MIT |
|
debug
npm
|
Transitive | 3.2.7 | 4.4.3 | 9 behind | — | MIT |
|
emoji-regex
npm
|
Transitive | 9.2.2 | 10.6.0 | 9 behind | — | MIT |
|
webidl-conversions
npm
|
Transitive | 3.0.1 | 8.0.1 | 9 behind | — | BSD-2-Clause |
|
isexe
npm
|
Transitive | 2.0.0 | 4.0.0 | 8 behind | — | ISC |
|
call-bind
npm
|
Transitive | 1.0.2 | 1.0.9 | 7 behind | — | MIT |
|
language-tags
npm
|
Transitive | 1.0.5 | 2.1.0 | 7 behind | — | MIT |
|
which
npm
|
Transitive | 2.0.2 | 7.0.0 | 7 behind | — | ISC |
|
balanced-match
npm
|
Transitive | 1.0.2 | 4.0.4 | 6 behind | — | MIT |
|
debug
npm
|
Transitive | 4.3.4 | 4.4.3 | 6 behind | — | MIT |
|
find-up
npm
|
Transitive | 5.0.0 | 8.0.0 | 6 behind | — | MIT |
|
object-inspect
npm
|
Transitive | 1.12.2 | 1.13.4 | 6 behind | — | MIT |
|
tsconfig-paths
npm
|
Transitive | 3.14.1 | 4.2.0 | 6 behind | — | MIT |
|
yocto-queue
npm
|
Transitive | 0.1.0 | 1.2.2 | 6 behind | — | MIT |
|
ansi-regex
npm
|
Transitive | 5.0.1 | 6.2.2 | 5 behind | — | MIT |
|
color-convert
npm
|
Transitive | 2.0.1 | 3.1.3 | 5 behind | — | MIT |
|
eslint-import-resolver-node
npm
|
Transitive | 0.3.6 | 0.4.0 | 5 behind | — | MIT |
|
esquery
npm
|
Transitive | 1.4.0 | 1.7.0 | 5 behind | — | BSD-3-Clause |
|
fast-glob
npm
|
Transitive | 3.2.11 | 3.3.3 | 5 behind | — | MIT |
|
internal-slot
npm
|
Transitive | 1.0.3 | 1.1.0 | 5 behind | — | MIT |
|
locate-path
npm
|
Transitive | 6.0.0 | 8.0.0 | 5 behind | — | MIT |
|
regexp.prototype.flags
npm
|
Transitive | 1.4.3 | 1.5.4 | 5 behind | — | MIT |
|
string.prototype.matchall
npm
|
Transitive | 4.0.7 | 4.0.12 | 5 behind | — | MIT |
|
strip-json-comments
npm
|
Transitive | 3.1.1 | 5.0.3 | 5 behind | — | MIT |
|
@humanwhocodes/object-schema
npm
|
Transitive | 1.2.1 | 2.0.3 | 4 behind | — | BSD-3-Clause |
|
array-includes
npm
|
Transitive | 3.1.5 | 3.1.9 | 4 behind | — | MIT |
|
minimist
npm
|
Transitive | 1.2.6 | 1.2.8 | 4 behind | — | MIT |
|
ms
npm
|
Transitive | 2.0.0 | 2.1.3 | 4 behind | — | MIT |
|
object.entries
npm
|
Transitive | 1.1.5 | 1.1.9 | 4 behind | — | MIT |
|
object.values
npm
|
Transitive | 1.1.5 | 1.2.1 | 4 behind | — | MIT |
|
parent-module
npm
|
Transitive | 1.0.1 | 3.2.0 | 4 behind | — | MIT |
|
punycode
npm
|
Transitive | 2.1.1 | 2.3.1 | 4 behind | — | MIT |
|
regenerator-runtime
npm
|
Transitive | 0.13.9 | 0.14.1 | 4 behind | — | MIT |
|
slash
npm
|
Transitive | 3.0.0 | 5.1.0 | 4 behind | — | MIT |
|
string.prototype.trimend
npm
|
Transitive | 1.0.5 | 1.0.9 | 4 behind | — | MIT |
|
@nodelib/fs.scandir
npm
|
Transitive | 2.1.5 | 4.0.1 | 3 behind | — | MIT |
|
@nodelib/fs.walk
npm
|
Transitive | 1.2.8 | 3.0.1 | 3 behind | — | MIT |
|
array.prototype.flat
npm
|
Transitive | 1.3.0 | 1.3.3 | 3 behind | — | MIT |
|
array.prototype.flatmap
npm
|
Transitive | 1.3.0 | 1.3.3 | 3 behind | — | MIT |
|
callsites
npm
|
Transitive | 3.1.0 | 4.2.0 | 3 behind | — | MIT |
|
color-name
npm
|
Transitive | 1.1.4 | 2.1.0 | 3 behind | — | MIT |
|
es-shim-unscopables
npm
|
Transitive | 1.0.0 | 1.1.0 | 3 behind | — | MIT |
|
function.prototype.name
npm
|
Transitive | 1.1.5 | 1.1.8 | 3 behind | — | MIT |
|
get-symbol-description
npm
|
Transitive | 1.0.0 | 1.1.0 | 3 behind | — | MIT |
|
glob-parent
npm
|
Transitive | 5.1.2 | 6.0.2 | 3 behind | — | ISC |
|
is-boolean-object
npm
|
Transitive | 1.1.2 | 1.2.2 | 3 behind | — | MIT |
|
object.assign
npm
|
Transitive | 4.1.4 | 4.1.7 | 3 behind | — | MIT |
|
object.fromentries
npm
|
Transitive | 2.0.5 | 2.0.8 | 3 behind | — | MIT |
|
object.hasown
npm
|
Transitive | 1.1.1 | 1.1.4 | 3 behind | — | MIT |
|
optionator
npm
|
Transitive | 0.9.1 | 0.9.4 | 3 behind | — | MIT |
|
side-channel
npm
|
Transitive | 1.0.4 | 1.1.0 | 3 behind | — | MIT |
|
string.prototype.trimstart
npm
|
Transitive | 1.0.5 | 1.0.8 | 3 behind | — | MIT |
|
strip-ansi
npm
|
Transitive | 6.0.1 | 7.2.0 | 3 behind | — | MIT |
|
@nodelib/fs.stat
npm
|
Transitive | 2.0.5 | 4.0.0 | 2 behind | — | MIT |
|
@types/json5
npm
|
Transitive | 0.0.29 | 2.2.0 | 2 behind | — | MIT |
|
array-union
npm
|
Transitive | 2.1.0 | 3.0.1 | 2 behind | — | MIT |
|
define-properties
npm
|
Transitive | 1.1.4 | 1.2.1 | 2 behind | — | MIT |
|
has-flag
npm
|
Transitive | 4.0.0 | 5.0.1 | 2 behind | — | MIT |
|
has-property-descriptors
npm
|
Transitive | 1.0.0 | 1.0.2 | 2 behind | — | MIT |
|
has-tostringtag
npm
|
Transitive | 1.0.0 | 1.0.2 | 2 behind | — | MIT |
|
import-fresh
npm
|
Transitive | 3.3.0 | 4.0.0 | 2 behind | — | MIT |
|
is-number-object
npm
|
Transitive | 1.0.7 | 1.1.1 | 2 behind | — | MIT |
|
is-regex
npm
|
Transitive | 1.1.4 | 1.2.1 | 2 behind | — | MIT |
|
is-shared-array-buffer
npm
|
Transitive | 1.0.2 | 1.0.4 | 2 behind | — | MIT |
|
is-string
npm
|
Transitive | 1.0.7 | 1.1.1 | 2 behind | — | MIT |
|
is-symbol
npm
|
Transitive | 1.0.4 | 1.1.1 | 2 behind | — | MIT |
|
is-weakref
npm
|
Transitive | 1.0.2 | 1.1.1 | 2 behind | — | MIT |
|
json-schema-traverse
npm
|
Transitive | 0.4.1 | 1.0.0 | 2 behind | — | MIT |
|
jsx-ast-utils
npm
|
Transitive | 3.3.3 | 3.3.5 | 2 behind | — | MIT |
|
language-subtag-registry
npm
|
Transitive | 0.3.22 | 0.4.2 | 2 behind | — | CC0-1.0 |
|
p-locate
npm
|
Transitive | 5.0.0 | 7.0.0 | 2 behind | — | MIT |
|
path-type
npm
|
Transitive | 4.0.0 | 6.0.0 | 2 behind | — | MIT |
|
strip-bom
npm
|
Transitive | 3.0.0 | 5.0.0 | 2 behind | — | MIT |
|
which-boxed-primitive
npm
|
Transitive | 1.0.2 | 1.1.1 | 2 behind | — | MIT |
|
ast-types-flow
npm
|
Transitive | 0.0.7 | 0.0.8 | 1 behind | — | ISC |
|
concat-map
npm
|
Transitive | 0.0.1 | 0.0.2 | 1 behind | — | MIT |
|
doctrine
npm
|
Transitive | 2.1.0 | 3.0.0 | 1 behind | — | Apache-2.0 AND BSD-2-Clause |
|
es-to-primitive
npm
|
Transitive | 1.2.1 | 1.3.0 | 1 behind | — | MIT |
|
escape-string-regexp
npm
|
Transitive | 4.0.0 | 5.0.0 | 1 behind | — | MIT |
|
fast-levenshtein
npm
|
Transitive | 2.0.6 | 3.0.0 | 1 behind | — | MIT |
|
fill-range
npm
|
Transitive | 7.0.1 | 7.1.1 | 1 behind | — | MIT |
|
function-bind
npm
|
Transitive | 1.1.1 | 1.1.2 | 1 behind | — | MIT |
|
has
npm
|
Transitive | 1.0.3 | 1.0.4 | 1 behind | — | MIT |
|
has-bigints
npm
|
Transitive | 1.0.2 | 1.1.0 | 1 behind | — | MIT |
|
has-symbols
npm
|
Transitive | 1.0.3 | 1.1.0 | 1 behind | — | MIT |
|
is-bigint
npm
|
Transitive | 1.0.4 | 1.1.0 | 1 behind | — | MIT |
|
is-date-object
npm
|
Transitive | 1.0.5 | 1.1.0 | 1 behind | — | MIT |
|
is-negative-zero
npm
|
Transitive | 2.0.2 | 2.0.3 | 1 behind | — | MIT |
|
json5
npm
|
Transitive | 1.0.2 | 2.2.3 | 1 behind | — | MIT |
|
ms
npm
|
Transitive | 2.1.2 | 2.1.3 | 1 behind | — | MIT |
|
path-exists
npm
|
Transitive | 4.0.0 | 5.0.0 | 1 behind | — | MIT |
|
path-is-absolute
npm
|
Transitive | 1.0.1 | 2.0.0 | 1 behind | — | MIT |
|
path-key
npm
|
Transitive | 3.1.1 | 4.0.0 | 1 behind | — | MIT |
|
resolve-from
npm
|
Transitive | 4.0.0 | 5.0.0 | 1 behind | — | MIT |
|
reusify
npm
|
Transitive | 1.0.4 | 1.1.0 | 1 behind | — | MIT |
|
shebang-regex
npm
|
Transitive | 3.0.0 | 4.0.0 | 1 behind | — | MIT |
|
unbox-primitive
npm
|
Transitive | 1.0.2 | 1.1.0 | 1 behind | — | MIT |
|
v8-compile-cache
npm
|
Transitive | 2.3.0 | 2.4.0 | 1 behind | — | MIT |
|
word-wrap
npm
|
Transitive | 1.2.4 | 1.2.5 | 1 behind | — | MIT |
License Breakdown
MIT
368
Apache-2.0
198
BSD-3-Clause
46
Unknown
39
ISC
20
BSD-2-Clause
19
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
12
MPL-2.0
9
BSD-3-Clause AND MIT
5
Apache-2.0 AND BSD-2-Clause
2
Apache-2.0 AND BSD-3-Clause
2
Apache-2.0 AND BSD-3-Clause AND MIT
2
Apache-2.0 AND CC-BY-SA-4.0
2
Apache-2.0 AND MIT
2
BSD-2-Clause OR (BSD-2-Clause AND Ruby)
2
BSD-2-Clause AND BSD-2-Clause-Views
1
BSD-2-Clause AND ISC
1
BSD-2-Clause-Views
1
CC0-1.0
1
CC0-1.0 AND MIT
1
ISC AND MIT
1
LicenseRef-scancode-unknown-license-reference AND MIT
1
MIT OR BSD-2-Clause
1
MPL-1.0 AND MPL-2.0
1
Python-2.0
1
Ruby OR (BSD-2-Clause AND Ruby)
1
Ruby OR (GPL-2.0 AND GPL-2.0-only) OR (GPL-2.0 AND Ruby) OR (GPL-2.0-only AND Ruby)
1
Unlicense
1
CVE Severity
critical
4
high
22
medium
19
low
2
unknown
1