PlannedPlanned for Package Risk
deps.dev (Open Source Insights)
What it is
Google's dependency graph, licence, version and project health data for open source packages.
Publisher and URL
Google.
Licence
Data generated by deps.dev, such as resolved dependencies, advisory statistics and associations, is available under CC-BY 4.0. Package data it collects from registries stays under those registries' terms. The API is used under Google's terms of service.
Update cadence
Commonly used packages are usually current within an hour or so; rarely updated packages can be older. We plan to look up on demand and cache for 24 hours.
Fields we use
Package version, SPDX licences, deprecated flag, published date, advisories, linked project, stars, OpenSSF Scorecard.
Known gaps
- No data for C or C++, which have no common packaging system.
- Licence detection reads package metadata and can be wrong.
How Stackbyte will use it
Will supply the licence and maintenance signals in Package Risk.