Dependency Analysis
zot
Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.
100%
Freshness
588
Dependencies
0
Outdated
0
Stale
—
Avg Behind
Dependency List
Latest release v2.1.16
| Dependency | Type | Current | Latest | Behind | CVE | License |
|---|---|---|---|---|---|---|
|
github.com/distribution/distribution/v3
golang
|
Direct | v3.1.0 | — | — | 1 medium | Unknown |
|
github.com/aquasecurity/trivy
golang
|
Direct | v0.70.0 | — | — | 1 unknown | Unknown |
|
github.com/aws/aws-sdk-go
golang
|
Direct | v1.55.8 | — | — | 2 unknown | Apache-2.0 |
|
github.com/sigstore/cosign/v2
golang
|
Direct | v2.6.2 | — | — | 1 unknown | Unknown |
License Breakdown
Apache-2.0
172
MIT
144
Unknown
138
BSD-3-Clause
42
Apache-2.0 AND BSD-3-Clause
15
BSD-2-Clause
14
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang
13
MPL-2.0
12
LicenseRef-scancode-generic-cla AND MIT
5
Apache-2.0 AND MIT
4
Unlicense
3
Apache-2.0 AND BSD-3-Clause AND MIT
2
Apache-2.0 AND CC-BY-SA-4.0
2
ISC
2
Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause
1
Apache-2.0 AND CC-BY-3.0 AND MIT
1
Apache-2.0 AND CC-BY-4.0
1
Apache-2.0 AND CC-BY-4.0 AND GPL-2.0
1
Apache-2.0 AND LicenseRef-scancode-dco-1.1
1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT
1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference
1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference AND MIT
1
Apache-2.0 OR (Apache-2.0 AND GPL-2.0-only)
1
BSD-2-Clause AND BSD-3-Clause
1
BSD-2-Clause AND ISC
1
BSD-2-Clause-Views
1
BSD-3-Clause AND MPL-2.0
1
CC-BY-3.0 AND MIT
1
CC0-1.0
1
LicenseRef-scancode-dco-1.1 AND LicenseRef-scancode-generic-cla AND MIT
1
LicenseRef-scancode-public-domain-disclaimer
1
LicenseRef-scancode-unknown-license-reference AND MIT
1
MIT-0
1
CVE Severity
critical
0
high
0
medium
1
low
0
unknown
3