Attribution
Almost nothing here is our data. Libyears reads public registries and advisory databases, joins them to your lockfiles, and does arithmetic. The value is in the joining and the judgement; the facts belong to the people below.
Data sources
The last column is the one that matters if you are reviewing this for a client. A private package name is never sent to any of them.
Ideas and formats
What we give back
The lockfile parsers, the freshness metrics, the npm registry client and the CLI are MIT-licensed and published as @libyears/parsers, @libyears/metrics, @libyears/registry and @libyears/cli. They are the parts most likely to break on a new lockfile format, and the parts that benefit most from someone else’s bug report.
npx @libyears/cli prints the same numbers this product does, offline, with no account. If that is all you need, it is all you need.
Your own inventory
Every repository can be exported as CSV or as a CycloneDX 1.6 document, including the freshness figures as vendor properties. Nothing here is a format you have to stay for; see the security page for how to take it and go.