Dependency health Explore packages

Explore packages

Find the package you depend on.

Search by name and registry. Open a package for maintenance trends, project details, release and licence history, incident reports and alternatives where available.

i
Search up to 50 package names separated by commas or semicolons, for example express, ast. Each name is matched separately. Pick registries to narrow it, or leave all ecosystems unchecked and every match is listed — django on npm and on PyPI are two rows. A Go module is its import path, like github.com/gorilla/mux. No match? You can ask for the package to be judged.
Search help

Separate package names with commas. Choose ecosystems in the filter menu, or leave them unchecked to include all. Clear filters

Packages assessed · 5,967

Packages with a current assessment.

All assessed packages →
PackageStatusHealthSecurity
clickhouse-connectpypiactive97 /100
clickhouse-driverpypiactive78 /100
clipboard-wincratescoasting76 /100
closedxmlnugetactive74 /100
cloud.google.com/gogoactive85 /100
cloud.google.com/go/bigquerygoactive90 /100
cloud.google.com/go/pubsubgoactive90 /100
cloud.google.com/go/storagegoactive90 /100
cloudeventspypiactive76 /100
cloudpathlibpypiactive86 /100
cloudpicklepypiactive84 /100
clrucratescoasting56 /100
cmakecratescoasting81 /100
cmakepypiactive95 /100
cmovcratesactive83 /100
co-mochanpmfinished44 /100
coanpmfinished30 /100
cobblepypifinished43 /100
cobscratescoasting87 /100
code.gitea.io/giteagoactive97 /100
codeownerspypiactive73 /100
coderayrubygemsfinished32 /100
codespan-reportingcratescoasting70 /100
codespellpypiactive91 /100
coffee-railsrubygemsfinished28 /100
coffee-scriptrubygemsfinished39 /100
coffee-script-sourcerubygemsunknown38 /100
coherepypiactive85 /100
color-convertnpmcoasting55 /100
⚠ Caution
Documented supply-chain incident

Check your installed version against the affected releases. This historical report does not mean every version is compromised.

· Aikido Security
Affected versions: Affected releases differ by package; see the original report.

Read incident details →
color-eyrecratesactive84 /100
color-namenpmactive91 /100
⚠ Caution
Documented supply-chain incident

Check your installed version against the affected releases. This historical report does not mean every version is compromised.

· Aikido Security
Affected versions: Affected releases differ by package; see the original report.

Read incident details →
color-spantracecratesactive84 /100
color_quantcratescoasting83 /100
coloramapypicoasting49 /100
colorchoicecratesactive80 /100
colorclasspypiabandoned10 /100
coloredcratescoasting66 /100
colored2rubygemsfinished52 /100
coloredlogspypifinished28 /100
colorfulpypicoasting60 /100
colorlogpypiactive95 /100
colorsnpmfinished36 /100
com.fasterxml.jackson.core:jackson-annotationsmavenactive82 /100
com.fasterxml.jackson.core:jackson-coremavenactive92 /100
com.fasterxml.jackson.core:jackson-databindmavenactive96 /100
com.fasterxml.jackson.module:jackson-module-scalamavenactive73 /100
com.google.code.gson:gsonmavenactive84 /100
com.google.code.gson:gson-extrasmavenactive80 /100
com.google.code.gson:protomavenactive80 /100
com.google.guava:failureaccessmavenactive92 /100

Repository trendlines

Historical activity for three widely used projects. Open any package to see its own chart.

Checking several dependencies? Check a project →