Skip to content
Tools / zot / Dependencies

Dependency Analysis

zot

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

100% Freshness
588 Dependencies
0 Outdated
0 Stale
Avg Behind

Dependency List

Latest release v2.1.16

Dependency Type Current Latest Behind CVE License
github.com/spdx/tools-golang
golang
Direct v0.5.7 Apache-2.0 AND CC-BY-4.0 AND GPL-2.0
github.com/theupdateframework/go-tuf/v2
golang
Direct v2.4.1 Apache-2.0 OR (Apache-2.0 AND GPL-2.0-only)

License Breakdown

Apache-2.0 172
MIT 144
Unknown 138
BSD-3-Clause 42
Apache-2.0 AND BSD-3-Clause 15
BSD-2-Clause 14
BSD-3-Clause AND LicenseRef-scancode-google-patent-license-golang 13
MPL-2.0 12
LicenseRef-scancode-generic-cla AND MIT 5
Apache-2.0 AND MIT 4
Unlicense 3
Apache-2.0 AND BSD-3-Clause AND MIT 2
Apache-2.0 AND CC-BY-SA-4.0 2
ISC 2
Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause 1
Apache-2.0 AND CC-BY-3.0 AND MIT 1
Apache-2.0 AND CC-BY-4.0 1
Apache-2.0 AND CC-BY-4.0 AND GPL-2.0 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 1
Apache-2.0 AND LicenseRef-scancode-dco-1.1 AND MIT 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference 1
Apache-2.0 AND LicenseRef-scancode-unknown-license-reference AND MIT 1
Apache-2.0 OR (Apache-2.0 AND GPL-2.0-only) 1
BSD-2-Clause AND BSD-3-Clause 1
BSD-2-Clause AND ISC 1
BSD-2-Clause-Views 1
BSD-3-Clause AND MPL-2.0 1
CC-BY-3.0 AND MIT 1
CC0-1.0 1
LicenseRef-scancode-dco-1.1 AND LicenseRef-scancode-generic-cla AND MIT 1
LicenseRef-scancode-public-domain-disclaimer 1
LicenseRef-scancode-unknown-license-reference AND MIT 1
MIT-0 1

CVE Severity

critical 0
high 0
medium 1
low 0
unknown 3

Beta — feedback welcome: [email protected]