Skip to main content
FOSSA Logo

Open source packages

Reference pages for open source packages across npm, PyPI, and Maven. Each page shows the top-level declared license, known CVE-linked advisories, version history, and the licenses that appear across the package's transitive dependency tree. Package metadata comes from the public registries and deps.dev, advisory data from OSV; FOSSA builds the same view against your own codebase, where a full scan detects licenses that declared metadata misses.

Most in-demand packages

Licenses shown are each package's top-level declared license.

  • eslint-plugin-react-hooksnpmThe library for web and native user interfaces.
    MITNo known CVE-linked advisories
  • langchain-openaiPyPIThe agent engineering platform.
    MITNo known CVE-linked advisories
  • jsdomnpmA JavaScript implementation of various web standards, for use with Node.js
    MITNo known CVE-linked advisories
  • dbt-corePyPIdbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications.
    Apache-2.0No known CVE-linked advisories
  • org.apache.logging.log4j:log4j-coreMavenApache Log4j is a versatile, feature-rich, efficient logging API and backend for Java.
    Apache-2.0Low severity advisories

Recently updated

Licenses shown are each package's top-level declared license.

  • dbt-corePyPIdbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications.
    v1.12.3 Aug 2026Apache-2.0No known CVE-linked advisories
  • langchain-openaiPyPIThe agent engineering platform.
    v1.6.0 Aug 2026MITNo known CVE-linked advisories
  • jsdomnpmA JavaScript implementation of various web standards, for use with Node.js
    v30.0.1 Jul 2026MITNo known CVE-linked advisories
  • eslint-plugin-react-hooksnpmThe library for web and native user interfaces.
    v7.1.1 Apr 2026MITNo known CVE-linked advisories
  • org.apache.logging.log4j:log4j-coreMavenApache Log4j is a versatile, feature-rich, efficient logging API and backend for Java.
    v3.0.0-beta3 Nov 2024Apache-2.0Low severity advisories

Browse every package

These pages read declared metadata. Run the same license and vulnerability view across your dependencies, where a full scan resolves what metadata leaves out.

Scan free

Dependency graph and package metadata from deps.dev (Google Open Source Insights), used under CC BY 4.0.

Vulnerability data from the Open Source Vulnerability (OSV) database, including the GitHub Advisory Database and the PyPI Advisory Database, used under CC BY 4.0. Only CVE-linked advisories are shown.

License and vulnerability information on this page is derived from public package metadata and public advisory databases. It is not legal advice, and it reflects the top-level declared license only. Verify the license and terms of any software for your own needs.