Dependency health Explore packages

Explore packages

Find the package you depend on.

Search by name and registry. Open a package for maintenance trends, project details, release and licence history, incident reports and alternatives where available.

i
Search up to 50 package names separated by commas or semicolons, for example express, ast. Each name is matched separately. Pick registries to narrow it, or leave all ecosystems unchecked and every match is listed — django on npm and on PyPI are two rows. A Go module is its import path, like github.com/gorilla/mux. No match? You can ask for the package to be judged.
Search help

Separate package names with commas. Choose ecosystems in the filter menu, or leave them unchecked to include all. Clear filters

Packages assessed · 8,824

Packages with a current assessment.

All assessed packages →
PackageStatusHealthSecurity
org.springframework:spring-beansmavenactive97 /100
⚠ Caution
Known vulnerability history

Package identity match only. Installed version and deployment have not been assessed.

CVE-2022-22965 · Spring4Shell ↗
Historical affected branches include 5.3.0–5.3.17 and 5.2.19 and earlier. Exploitability depends on runtime and deployment; consult Spring’s advisory.

View package context →
org.springframework:spring-bindingmavenunknown38 /100
org.springframework:spring-contextmavenactive97 /100
org.springframework:spring-context-indexermavenactive97 /100
org.springframework:spring-context-supportmavenactive97 /100
org.springframework:spring-coremavenactive97 /100
org.springframework:spring-core-testmavenactive97 /100
org.springframework:spring-daomavenunknown38 /100
org.springframework:spring-expressionmavenactive97 /100
org.springframework:spring-hibernatemavenunknown38 /100
org.springframework:spring-hibernate2mavenunknown38 /100
org.springframework:spring-hibernate3mavenunknown38 /100
org.springframework:spring-ibatismavenunknown38 /100
org.springframework:spring-instrumentmavenactive97 /100
org.springframework:spring-instrument-tomcatmavenactive80 /100
org.springframework:spring-javaconfigmavendead0 /100
org.springframework:spring-jcamavenunknown38 /100
org.springframework:spring-jclmavenactive97 /100
org.springframework:spring-jdbcmavenactive97 /100
org.springframework:spring-webfluxmavenactive97 /100
⚠ Caution
Known vulnerability history

Package identity match only. Installed version and deployment have not been assessed.

CVE-2022-22965 · Spring4Shell ↗
Historical affected branches include 5.3.0–5.3.17 and 5.2.19 and earlier. Exploitability depends on runtime and deployment; consult Spring’s advisory.

View package context →
org.springframework:spring-webmvcmavenactive97 /100
⚠ Caution
Known vulnerability history

Package identity match only. Installed version and deployment have not been assessed.

CVE-2022-22965 · Spring4Shell ↗
Historical affected branches include 5.3.0–5.3.17 and 5.2.19 and earlier. Exploitability depends on runtime and deployment; consult Spring’s advisory.

View package context →
orjsonpypiactive88 /100
orm_adapterrubygemsfinished39 /100
ormsgpackpypiactive67 /100
osrubygemsfinished39 /100
os_infocratescoasting72 /100
os_pipecratescoasting79 /100
os_str_bytescratesactive89 /100
oscryptopypiactive55 /100
oss2pypiunknown48 /100
ostructrubygemsactive78 /100
otp.netnugetcoasting74 /100
ouroboroscratesfinished31 /100
ouroboros_macrocratesfinished31 /100
outcomepypifinished25 /100
outrefcratesfinished61 /100
overlayscrollbars-vuenpmcoasting68 /100
overloadcratesfinished47 /100
overridespypicoasting65 /100
owned_ttf_parsercratescoasting72 /100
owo-colorscratesactive90 /100
oxrubygemsactive98 /100
p256cratesactive87 /100
p384cratesactive87 /100
packageurl-pythonpypicoasting60 /100
packagingpypiactive86 /100
pactrubygemsactive91 /100
pact-mock_servicerubygemsactive73 /100
pact-supportrubygemsactive91 /100
page_sizecratesfinished25 /100

Repository trendlines

Historical activity for three widely used projects. Open any package to see its own chart.

Checking several dependencies? Check a project →