Nobuf

Package & Dependency Risk Inspector

Live data

Inspect versions, licenses, dependency graphs, and known OSV vulnerabilities across package ecosystems.

Choose an ecosystem and inspect a public package.

How to use it

  1. 01

    Choose a package and version

    Select an ecosystem, enter its canonical package name, and choose a published version from deps.dev.

  2. 02

    Review dependencies and risk

    Inspect licenses, project links, resolved direct and transitive dependencies, OSV severity, affected ranges, and fixed versions.

  3. 03

    Compare before upgrading

    Compare dependency, vulnerability, and license totals between two versions and copy the ecosystem-specific install command.

Frequently asked questions

Which ecosystems are supported?

Package and version metadata supports npm, PyPI, Maven, Cargo, Go, NuGet, and RubyGems. Resolved dependency graphs depend on deps.dev coverage and are currently available for npm, PyPI, Maven, and Cargo.

Does no known vulnerability mean the package is secure?

No. OSV reports known published advisories. It cannot detect unpublished flaws, malicious behavior, unsafe configuration, compromised maintainers, or vulnerabilities outside indexed data.

Is the license result legal advice?

No. License identifiers come from package metadata or automated detection. Verify source files, exceptions, combined-work obligations, and current terms with qualified counsel.

What does the dependency graph represent?

It approximates resolving that package on deps.dev's generic environment. Optional features, platforms, private registries, lockfiles, and your application constraints can produce a different graph.

Keep working with other focused browser utilities.

All tools

Local by default; remote data sources are clearly disclosed.

© 2026 Nobuf

Nobuf

Fast, local-first utilities powered by your browser.