Skip to content
Tools / ydb / Dependencies

Dependency Analysis

ydb

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

55% Freshness
159 Dependencies
62 Outdated
0 Stale
15.9 Avg Behind

Dependency List

Latest release 25.3.1.25

Dependency Type Current Latest Behind CVE License
virtualenv
pypi
Direct 20.23.0 21.4.2 60 behind 2 high MIT
black
pypi
Direct 23.3.0 26.5.1 28 behind 2 high MIT
urllib3
pypi
Direct 2.0.2 2.7.0 23 behind 7 high MIT
certifi
pypi
Direct 2023.5.7 2026.5.20 19 behind 2 high MPL-2.0
gunicorn
pypi
Direct 21.2.0 26.0.0 13 behind 2 high MIT
com.google.protobuf:protobuf-java
maven
Direct 3.21.7 1 high BSD-3-Clause
com.google.protobuf:protobuf-java
maven
Direct 3.21.1 3 high BSD-3-Clause
com.google.protobuf:protobuf-javalite
maven
Direct 3.21.7 1 high BSD-3-Clause
filelock
pypi
Direct 3.12.0 3.29.1 40 behind 2 medium Unlicense
pytest
pypi
Direct 7.3.1 9.0.3 30 behind 1 medium MIT
zipp
pypi
Direct 3.15.0 4.1.0 19 behind 1 medium MIT
requests
pypi
Direct 2.31.0 2.34.2 12 behind 3 medium Apache-2.0
jinja2
pypi
Direct 3.1.2 3.1.6 4 behind 5 medium BSD-2-Clause AND BSD-3-Clause
idna
pypi
Direct 3.4 3.18.0 1 medium BSD-2-Clause AND BSD-3-Clause
pygments
pypi
Direct 2.15.1 2.20.0 10 behind 1 low BSD-2-Clause
flask
pypi
Direct 2.3.3 3.1.3 8 behind 1 low BSD-2-Clause AND BSD-3-Clause

License Breakdown

Unknown 45
MIT 35
Apache-2.0 34
BSD-2-Clause AND BSD-3-Clause 12
BSD-2-Clause 10
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 8
BSD-3-Clause 5
MPL-2.0 2
0BSD AND BSD-2-Clause AND BSD-3-Clause 1
Apache-2.0 AND BSD-2-Clause 1
CDDL-1.0 OR GPL-2.0-only WITH Classpath-exception-2.0 1
GPL-3.0-or-later AND LGPL-2.1-or-later 1
Python-2.0 1
Python-2.0.1 1
Unlicense 1

CVE Severity

critical 0
high 8
medium 6
low 2
unknown 0

Beta — feedback welcome: [email protected]