Skip to content
Tools / zigbee2mqtt / Dependencies

Dependency Analysis

zigbee2mqtt

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

56% Freshness
337 Dependencies
117 Outdated
0 Stale
6.1 Avg Behind

Dependency List

Latest release 2.10.0

Dependency Type Current Latest Behind CVE License
vite
npm
Transitive 6.3.5 8.0.16 83 behind 5 high Apache-2.0 AND BSD-2-Clause AND CC0-1.0 AND ISC AND MIT
minimatch
npm
Transitive 9.0.5 10.2.5 36 behind 3 high ISC
picomatch
npm
Transitive 4.0.2 4.0.4 4 behind 2 high MIT
fast-uri
npm
Transitive 3.1.0 3.1.2 2 behind 2 high BSD-3-Clause
rollup
npm
Transitive 4.44.0 1 high 0BSD AND ISC AND MIT
brace-expansion
npm
Transitive 5.0.2 5.0.6 9 behind 1 medium MIT
postcss
npm
Transitive 8.5.6 8.5.15 9 behind 1 medium MIT
ip-address
npm
Transitive 10.1.0 10.2.0 2 behind 1 medium MIT

License Breakdown

MIT 255
ISC 18
Unknown 18
BlueOak-1.0.0 10
BSD-3-Clause 8
MIT OR Apache-2.0 8
Apache-2.0 3
Apache-2.0 AND MIT 2
GPL-3.0-or-later 2
0BSD 1
0BSD AND ISC AND MIT 1
Apache-2.0 AND BSD-2-Clause AND CC0-1.0 AND ISC AND MIT 1
BSD-3-Clause AND ISC AND MIT 1
GPL-2.0 OR MIT OR (GPL-2.0 AND MIT) 1
GPL-3.0 1
GPL-3.0-only OR MIT 1
ISC AND MIT 1
LicenseRef-scancode-dco-1.1 AND MIT 1
MIT AND Zlib 1
Python-2.0 1
Unlicense 1

CVE Severity

critical 0
high 5
medium 3
low 0
unknown 0

Beta — feedback welcome: [email protected]