Dependency Analysis
yubal
Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.
91%
Freshness
143
Dependencies
5
Outdated
0
Stale
4.8
Avg Behind
Dependency List
Latest release v0.8.0
| Dependency | Type | Current | Latest | Behind | CVE | License |
|---|---|---|---|---|---|---|
|
react
npm
|
Direct | 19.2.4 | 19.2.7 | 131 behind | — | MIT |
|
react-dom
npm
|
Direct | 19.2.4 | 19.2.7 | 131 behind | — | MIT |
|
numpy
pypi
|
Transitive | 1.26.4 | 2.4.6 | 28 behind | — | BSD-2-Clause AND BSD-3-Clause |
|
ty
pypi
|
Direct | 0.0.33 | 0.0.43 | 10 behind | — | Unknown |
|
pytest-asyncio
pypi
|
Direct | 1.3.0 | 1.4.0 | 4 behind | — | Apache-2.0 |
|
requests
pypi
|
Transitive | 2.33.1 | 2.34.2 | 4 behind | — | Apache-2.0 |
|
starlette
pypi
|
Transitive | 1.0.0 | 1.2.1 | 4 behind | — | BSD-3-Clause |
|
httpx
pypi
|
Transitive | 0.28.1 | 1.0.0.dev3 | 3 behind | — | BSD-3-Clause |
|
ruff
pypi
|
Direct | 0.15.12 | 0.15.15 | 3 behind | — | MIT |
|
uvicorn
pypi
|
Transitive | 0.46.0 | 0.49.0 | 3 behind | — | BSD-3-Clause |
|
click
pypi
|
Transitive | 8.3.3 | 8.4.1 | 2 behind | — | BSD-3-Clause |
|
coverage
pypi
|
Transitive | 7.13.5 | 7.14.1 | 2 behind | — | Apache-2.0 |
|
markdown-it-py
pypi
|
Transitive | 4.0.0 | 4.2.0 | 2 behind | — | MIT |
|
pydantic-core
pypi
|
Transitive | 2.46.3 | 2.47.0 | 2 behind | — | Unknown |
|
sqlalchemy
pypi
|
Transitive | 2.0.49 | 2.0.50 | 2 behind | — | MIT |
|
certifi
pypi
|
Transitive | 2026.4.22 | 2026.5.20 | 1 behind | — | MPL-2.0 |
|
fastapi
pypi
|
Transitive | 0.136.1 | 0.136.3 | 1 behind | — | MIT |
|
greenlet
pypi
|
Transitive | 3.5.0 | 3.5.1 | 1 behind | — | MIT AND PSF-2.0 |
|
httptools
pypi
|
Direct | 0.7.1 | 0.8.0 | 1 behind | — | MIT |
|
pydantic
pypi
|
Transitive | 2.13.3 | 2.13.4 | 1 behind | — | MIT |
|
pydantic-settings
pypi
|
Transitive | 2.14.0 | 2.14.1 | 1 behind | — | MIT |
|
pytest-socket
pypi
|
Direct | 0.7.0 | 0.8.0 | 1 behind | — | MIT |
|
urllib3
pypi
|
Transitive | 2.6.3 | 2.7.0 | 1 behind | — | MIT |
|
watchfiles
pypi
|
Direct | 1.1.1 | 1.2.0 | 1 behind | — | MIT |
|
@eslint/js
npm
|
Direct | ^10.0.1 | 10.0.1 | — | — | Unknown |
|
@eslint/js
npm
|
Direct | ^10.0.1 | 10.0.1 | — | — | Unknown |
|
@formkit/tempo
npm
|
Direct | ^1.0.0 | — | — | — | Unknown |
|
@heroui/react
npm
|
Direct | ^2.8.10 | — | — | — | Unknown |
|
@playwright/test
npm
|
Direct | ^1.52.0 | 1.60.0 | — | — | Unknown |
|
@tailwindcss/vite
npm
|
Direct | ^4.2.1 | 4.3.0 | — | — | Unknown |
|
@tailwindcss/vite
npm
|
Direct | ^4.2.4 | 4.3.0 | — | — | Unknown |
|
@tanstack/react-router
npm
|
Direct | ^1.169.1 | — | — | — | Unknown |
|
@types/bun
npm
|
Direct | ^1.3.13 | — | — | — | Unknown |
|
@types/node
npm
|
Direct | ^25.6.0 | 25.9.1 | — | — | Unknown |
|
@types/react
npm
|
Direct | ^19.2.14 | 19.2.16 | — | — | Unknown |
|
@types/react-dom
npm
|
Direct | ^19.2.3 | 19.2.3 | — | — | Unknown |
|
@vitejs/plugin-react
npm
|
Direct | ^6.0.1 | 6.0.2 | — | — | Unknown |
|
@wxt-dev/auto-icons
npm
|
Direct | ^1.1.1 | — | — | — | Unknown |
|
actions/attest-build-provenance
githubactions
|
Direct | 4.*.* | — | — | — | Unknown |
|
actions/cache
githubactions
|
Direct | 5.*.* | — | — | — | Unknown |
|
actions/checkout
githubactions
|
Direct | 6.*.* | — | — | — | Unknown |
|
alembic
|
Direct | — | — | — | — | Unknown |
|
alembic
pypi
|
Transitive | 1.18.4 | 1.18.4 | Current | — | MIT |
|
annotated-doc
pypi
|
Transitive | 0.0.4 | 0.0.4 | Current | — | MIT |
|
annotated-types
pypi
|
Transitive | 0.7.0 | 0.7.0 | Current | — | MIT |
|
anyio
pypi
|
Transitive | 4.13.0 | 4.13.0 | Current | — | MIT |
|
charset-normalizer
pypi
|
Transitive | 3.4.7 | 3.4.7 | Current | — | MIT |
|
codecov/codecov-action
githubactions
|
Direct | 6.*.* | — | — | — | Unknown |
|
colorama
pypi
|
Transitive | 0.4.6 | 0.4.6 | Current | — | BSD-2-Clause AND BSD-3-Clause |
|
cron-parser
npm
|
Direct | ^5.5.0 | 5.5.0 | — | — | Unknown |
|
croniter
|
Direct | — | — | — | — | Unknown |
|
croniter
pypi
|
Transitive | 6.2.2 | 6.2.2 | Current | — | Unknown |
|
deno
|
Direct | — | — | — | — | Unknown |
|
deno
pypi
|
Transitive | 2.7.14 | — | — | — | Unknown |
|
docker/build-push-action
githubactions
|
Direct | 7.*.* | — | — | — | Unknown |
|
docker/login-action
githubactions
|
Direct | 4.*.* | — | — | — | Unknown |
|
docker/metadata-action
githubactions
|
Direct | 6.*.* | — | — | — | Unknown |
|
docker/setup-buildx-action
githubactions
|
Direct | 4.*.* | — | — | — | Unknown |
|
docker/setup-qemu-action
githubactions
|
Direct | 4.*.* | — | — | — | Unknown |
|
eslint
npm
|
Direct | ^10.0.2 | 10.4.1 | — | — | Unknown |
|
eslint
npm
|
Direct | ^10.2.1 | 10.4.1 | — | — | Unknown |
|
eslint-config-prettier
npm
|
Direct | ^10.1.8 | 10.1.8 | — | — | Unknown |
|
eslint-config-prettier
npm
|
Direct | ^10.1.8 | 10.1.8 | — | — | Unknown |
|
eslint-plugin-react-hooks
npm
|
Direct | ^7.1.1 | — | — | — | Unknown |
|
eslint-plugin-react-refresh
npm
|
Direct | ^0.5.2 | 0.5.2 | — | — | Unknown |
|
fastapi
|
Direct | — | — | — | — | Unknown |
|
filetype
pypi
|
Transitive | 1.2.0 | 1.2.0 | Current | — | MIT |
|
globals
npm
|
Direct | ^17.4.0 | — | — | — | Unknown |
|
globals
npm
|
Direct | ^17.5.0 | 17.6.0 | — | — | Unknown |
|
h11
pypi
|
Transitive | 0.16.0 | 0.16.0 | Current | — | MIT |
|
httpcore
pypi
|
Transitive | 1.0.9 | 1.0.9 | Current | — | BSD-2-Clause AND BSD-3-Clause |
|
httpx
|
Direct | — | — | — | — | Unknown |
|
idna
pypi
|
Transitive | 3.13 | 3.18.0 | — | — | BSD-3-Clause |
|
iniconfig
pypi
|
Transitive | 2.3.0 | 2.3.0 | Current | — | MIT |
|
jdx/mise-action
githubactions
|
Direct | 4.*.* | — | — | — | Unknown |
|
lucide-react
npm
|
Direct | ^0.577.0 | 1.17.0 | — | — | Unknown |
|
lucide-static
npm
|
Direct | ^0.577.0 | — | — | — | Unknown |
|
mako
pypi
|
Transitive | 1.3.12 | 1.3.12 | Current | — | Unknown |
|
markupsafe
pypi
|
Transitive | 3.0.3 | 3.0.3 | Current | — | BSD-3-Clause |
|
mdurl
pypi
|
Transitive | 0.1.2 | 0.1.2 | Current | — | MIT |
|
mediafile
|
Direct | — | — | — | — | Unknown |
|
mediafile
pypi
|
Transitive | 0.17.0 | — | — | — | Unknown |
|
motion
npm
|
Direct | ^12.38.0 | 12.40.0 | — | — | Unknown |
|
mutagen
pypi
|
Transitive | 1.47.0 | — | — | — | GPL-2.0 AND GPL-2.0-or-later AND GPL-3.0-or-later |
|
numpy
|
Direct | — | — | — | — | Unknown |
|
openapi-fetch
npm
|
Direct | 0.17.0 | 0.17.0 | Current | — | MIT |
|
openapi-typescript
npm
|
Direct | ^7.13.0 | 7.13.0 | — | — | Unknown |
|
packaging
pypi
|
Transitive | 26.2 | 26.2.0 | — | — | Apache-2.0 AND BSD-2-Clause |
|
pathvalidate
|
Direct | — | — | — | — | Unknown |
|
pathvalidate
pypi
|
Transitive | 3.3.1 | 3.3.1 | Current | — | MIT |
|
pluggy
pypi
|
Transitive | 1.6.0 | 1.6.0 | Current | — | MIT |
|
prettier
npm
|
Direct | ^3.8.1 | 3.8.3 | — | — | Unknown |
|
prettier
npm
|
Direct | ^3.8.3 | 3.8.3 | — | — | Unknown |
|
prettier-plugin-tailwindcss
npm
|
Direct | ^0.7.2 | 0.8.0 | — | — | Unknown |
|
prettier-plugin-tailwindcss
npm
|
Direct | ^0.7.4 | — | — | — | Unknown |
|
pydantic
|
Direct | — | — | — | — | Unknown |
|
pydantic-settings
|
Direct | — | — | — | — | Unknown |
|
pygments
pypi
|
Transitive | 2.20.0 | 2.20.0 | Current | — | BSD-2-Clause |
|
pytest
pypi
|
Direct | 9.0.3 | 9.0.3 | Current | — | MIT |
|
pytest-cov
pypi
|
Direct | 7.1.0 | 7.1.0 | Current | — | MIT |
|
python-dateutil
pypi
|
Transitive | 2.9.0.post0 | 2.9.0.post0 | Current | — | Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference |
|
python-dotenv
pypi
|
Transitive | 1.2.2 | 1.2.2 | Current | — | BSD-3-Clause |
|
pyyaml
pypi
|
Direct | 6.0.3 | 6.0.3 | Current | — | MIT |
|
rapidfuzz
|
Direct | — | — | — | — | Unknown |
|
rapidfuzz
pypi
|
Transitive | 3.14.5 | 3.14.5 | Current | — | GPL-1.0-or-later AND MIT |
|
rich
|
Direct | — | — | — | — | Unknown |
|
rich
|
Direct | — | — | — | — | Unknown |
|
rich
pypi
|
Transitive | 15.0.0 | 15.0.0 | Current | — | MIT |
|
shellingham
pypi
|
Transitive | 1.5.4 | 1.5.4 | Current | — | ISC |
|
six
pypi
|
Transitive | 1.17.0 | 1.17.0 | Current | — | MIT |
|
softprops/action-gh-release
githubactions
|
Direct | 3.*.* | — | — | — | Unknown |
|
sqlmodel
|
Direct | — | — | — | — | Unknown |
|
sqlmodel
pypi
|
Transitive | 0.0.38 | 0.0.38 | Current | — | Unknown |
|
tailwindcss
npm
|
Direct | ^4.2.1 | 4.3.0 | — | — | Unknown |
|
tailwindcss
npm
|
Direct | ^4.2.4 | 4.3.0 | — | — | Unknown |
|
ts-pattern
npm
|
Direct | ^5.9.0 | — | — | — | Unknown |
|
typer
|
Direct | — | — | — | — | Unknown |
|
typer
pypi
|
Direct | 0.25.1 | — | — | — | Unknown |
|
typescript
npm
|
Direct | ^5.9.3 | 6.0.3 | — | — | Unknown |
|
typescript
npm
|
Direct | ^5.9.3 | 6.0.3 | — | — | Unknown |
|
typescript-eslint
npm
|
Direct | ^8.56.1 | — | — | — | Unknown |
|
typescript-eslint
npm
|
Direct | ^8.59.1 | — | — | — | Unknown |
|
typing-extensions
pypi
|
Transitive | 4.15.0 | 4.15.0 | Current | — | Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD |
|
typing-inspection
pypi
|
Transitive | 0.4.2 | 0.4.2 | Current | — | MIT |
|
tzdata
|
Direct | — | — | — | — | Unknown |
|
tzdata
pypi
|
Transitive | 2026.2 | 2026.2.0 | — | — | Apache-2.0 |
|
unidecode
|
Direct | — | — | — | — | Unknown |
|
unidecode
pypi
|
Transitive | 1.4.0 | — | — | — | BSD-3-Clause AND GPL-2.0 AND GPL-2.0-only AND GPL-2.0-or-later AND GPL-3.0-only |
|
uv-build
|
Direct | — | — | — | — | Unknown |
|
uv-build
|
Direct | — | — | — | — | Unknown |
|
uvicorn
|
Direct | — | — | — | — | Unknown |
|
uvloop
pypi
|
Direct | 0.22.1 | 0.22.1 | Current | — | Apache-2.0 AND MIT |
|
vanjs-core
npm
|
Direct | ^1.6.0 | — | — | — | Unknown |
|
vite
npm
|
Direct | ^8.0.10 | — | — | — | Unknown |
|
websockets
pypi
|
Direct | 16.0 | 16.0.0 | — | — | BSD-3-Clause |
|
wxt
npm
|
Direct | ^0.20.18 | — | — | — | Unknown |
|
yt-dlp
pypi
|
Direct | 2026.3.17 | — | — | — | Unknown |
|
yt-dlp
pypi
|
Transitive | 2026.3.17 | — | — | — | Unknown |
|
ytmusicapi
|
Direct | — | — | — | — | Unknown |
|
ytmusicapi
pypi
|
Transitive | 1.11.6.dev4+ga8a120f37 | — | — | — | Unknown |
|
yubal
|
Direct | — | — | — | — | Unknown |
|
yubal
pypi
|
Transitive | 0.8.0 | — | — | — | Unknown |
|
yubal-api
pypi
|
Direct | 0.8.0 | — | — | — | Unknown |
|
yubal-workspace
pypi
|
Direct | 0.8.0 | — | — | — | Unknown |
License Breakdown
Unknown
88
MIT
30
BSD-3-Clause
8
Apache-2.0
4
BSD-2-Clause AND BSD-3-Clause
3
Apache-2.0 AND BSD-2-Clause
1
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference
1
Apache-2.0 AND MIT
1
BSD-2-Clause
1
BSD-3-Clause AND GPL-2.0 AND GPL-2.0-only AND GPL-2.0-or-later AND GPL-3.0-only
1
GPL-1.0-or-later AND MIT
1
GPL-2.0 AND GPL-2.0-or-later AND GPL-3.0-or-later
1
ISC
1
MIT AND PSF-2.0
1
MPL-2.0
1
Python-2.0 AND GPL-1.0-or-later AND Python-2.0 AND BSD-3-Clause AND Python-2.0 AND BSD-3-Clause AND 0BSD
1
CVE Severity
critical
0
high
0
medium
0
low
0
unknown
0