{"package":"late","ecosystem":"pypi","latest_version":"1.2.2","description":"Late allows for late binding of default arguments","license":"GNU Lesser General Public v3 or later (LGPLv3+)","license_risk":"unknown","commercial_use_notes":"verify manually — license not parseable / not declared.","homepage":"https://pypi.org/project/Late/","repository":"https://github.com/neogeny/late","downloads_weekly":57,"health":{"score":31,"risk":"critical","breakdown":{"maintenance":0,"popularity":0,"security":25,"maturity":6,"community":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":1,"critical":0,"high":0,"medium":0,"low":1,"details":[{"vuln_id":"CVE-2025-64326","severity":"low","summary":"Weblate is a web based localization tool. In versions 5.14 and below,  Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.","affected_versions":"<5.14.1|=1.0.0|=1.0.0b1|=1.0.1|=1.0.2|=1.1.0|=1.1.1|=1.2.0|=1.2.1|=1.2.2","fixed_version":"5.14.1","source":"osv","published_at":"2025-11-06T21:15:43.957Z","in_kev":false,"epss_prob":0.00183,"epss_percentile":0.08135,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"1.2.2","total_count":9,"recent":["1.0.0b1","1.0.0","1.0.1","1.0.2","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":0,"first_published":null,"last_published":"2023-11-17T00:20:35.412417Z","dependencies_count":0,"dependencies":[]},"github_stats":null,"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"use_with_caution","issues":["Moderate health score (31/100) — verify manually"],"use_version":"1.2.2","version_hint":"Update to >= 5.14.1 to fix known vulnerabilities","summary":"late@1.2.2 low health (31/100) — consider alternatives"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/pypi/late","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/pypi/late","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/pypi/late","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate","hint_bulk":"You've called /api/check 6 times in 60s. Save bandwidth + tokens with POST /api/check_bulk (1 round-trip for N pkgs)."},"requested_version":null,"_cache":"hit","_response_ms":0,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":true,"targets":[{"legitimate_package":"lark","distance":2,"reason":"adjacent_swap_or_double"}]},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":false},"version_history_summary":{"total_versions":9,"first_release_age_days":null,"last_release_days_ago":983,"avg_days_between_releases":null,"release_velocity":"stale"}}