Skip to content
Tools / zot / Dependencies

Dependency Analysis

zot

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

100% Freshness
588 Dependencies
0 Outdated
0 Stale
Avg Behind

Dependency List

Latest release v2.1.16

Dependency Type Current Latest Behind CVE License
github.com/distribution/distribution/v3
golang
Direct v3.1.0 1 medium Unknown
github.com/aquasecurity/trivy
golang
Direct v0.70.0 1 unknown Unknown
github.com/aws/aws-sdk-go
golang
Direct v1.55.8 2 unknown Apache-2.0
github.com/sigstore/cosign/v2
golang
Direct v2.6.2 1 unknown Unknown

License Breakdown

Apache-2.0 172
MIT 144
Unknown 138
BSD-3-Clause 42
Apache-2.0 AND BSD-3-Clause 15
BSD-2-Clause 14
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 13
MPL-2.0 12
LicenseRef-scancode-generic-cla AND MIT 5
Apache-2.0 AND MIT 4
Unlicense 3
Apache-2.0 AND BSD-3-Clause AND MIT 2
Apache-2.0 AND CC-BY-SA-4.0 2
ISC 2
Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause 1
Apache-2.0 AND CC-BY-3.0 AND MIT 1
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC-BY-4.0 AND GPL-2.0 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference AND MIT 1
Apache-2.0 OR (Apache-2.0 AND GPL-2.0-only) 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-2-Clause AND ISC 1
BSD-2-Clause-Views 1
BSD-3-Clause AND MPL-2.0 1
CC-BY-3.0 AND MIT 1
CC0-1.0 1
LicenseRef-scancode-dco-1.1 AND LicenseRef-scancode-generic-cla AND MIT 1
LicenseRef-scancode-public-domain-disclaimer 1
LicenseRef-scancode-unknown-license-reference AND MIT 1
MIT-0 1

CVE Severity

critical 0
high 0
medium 1
low 0
unknown 3

Beta — feedback welcome: [email protected]