{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T11:49:05.682Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T11:47:56.369Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"repository","entity":{"id":"opencode:4609","slug":"opencode-4609","gitlabProjectId":4609,"name":"LLM_Workshop","pathWithNamespace":"bbsr_ida_public/llm_workshop","description":"This repository accompanies a three-day hands-on workshop on Large Language Models (LLMs), Prompt Engineering, and Retrieval-Augmented Generation (RAG). The workshop is designed to equip participants with practical skills and foundational knowledge to understand, deploy, and evaluate LLM-based applications across a wide range of fields.\r\nThe program combines a lecture series covering theoretical foundations with a programming workshop in Jupyter Notebooks. Participants explore core technologies such as OpenAI APIs, LangChain, vector databases, document parsing, and AI toolchains—supported by real-world examples and scientific documents.\r\nThe workshop is suitable for professionals, researchers, and students who seek a structured and practice-oriented introduction to state-of-the-art AI workflows based on LLMs.","webUrl":"https://gitlab.opencode.de/bbsr_ida_public/llm_workshop","commitSha":"fddd886ab2fd3824e269d40cefde90cbed709201","commitUrl":"https://gitlab.opencode.de/bbsr_ida_public/llm_workshop/-/commit/fddd886ab2fd3824e269d40cefde90cbed709201","lastActivityAt":"2025-05-02T11:59:04.875Z","headCommittedAt":"2025-05-02T11:58:35.000Z","tree":{"complete":true,"entryCount":67,"truncated":false},"files":[],"resolvedComponentCount":8,"artifactResolvedComponentCount":0,"exactManifestPinCount":8,"packageCount":8,"ecosystems":["pypi"],"aiPackageCount":8,"licenseExpressionCount":4,"unknownLicensePackageCount":0,"advisoryIds":["GHSA-3644-q5cj-c5c7","GHSA-45pg-36p6-83v9","GHSA-g48c-2wqr-h844","GHSA-gr75-jv2w-4656","GHSA-pc6w-59fv-rh23","GHSA-q25c-c977-4cmh","GHSA-r7w7-9xr2-qq2r","GHSA-w39p-vh2g-g8g5","PYSEC-2024-115","PYSEC-2024-323"],"advisoryCount":10,"providers":[{"id":"openai","label":"OpenAI"},{"id":"ollama","label":"Ollama"}]},"evidence":{"files":[{"path":"docker/requirements.txt","kind":"exact-manifest-pin","sourceUrl":"https://gitlab.opencode.de/bbsr_ida_public/llm_workshop/-/blob/fddd886ab2fd3824e269d40cefde90cbed709201/docker/requirements.txt","commitSha":"fddd886ab2fd3824e269d40cefde90cbed709201","blobSha":"0d707ff70a4c5b3584990d5380c8bf62c64284b5","state":"parsed","componentCount":8}],"occurrenceCount":8},"related":{"packages":[{"id":"package:pypi:langchain-community","slug":"langchain-community-b296254c","identity":"pypi:langchain-community","label":"LangChain Community","aiRelevant":true,"provider":null,"advisoryCount":4,"licenseExpressions":["MIT"],"versions":["0.3.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["docker/requirements.txt"]},{"id":"package:pypi:langchain","slug":"langchain-2b3b6a0b","identity":"pypi:langchain","label":"LangChain","aiRelevant":true,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["0.3.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["docker/requirements.txt"]},{"id":"package:pypi:langgraph","slug":"langgraph-6c1c645e","identity":"pypi:langgraph","label":"LangGraph","aiRelevant":true,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["0.3.21"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["docker/requirements.txt"]},{"id":"package:pypi:langchain-openai","slug":"langchain-openai-4985188e","identity":"pypi:langchain-openai","label":"LangChain OpenAI","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.2.8"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["docker/requirements.txt"]},{"id":"package:pypi:ollama","slug":"ollama-0b25d881","identity":"pypi:ollama","label":"Ollama SDK","aiRelevant":true,"provider":{"id":"ollama","label":"Ollama"},"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["docker/requirements.txt"]},{"id":"package:pypi:openai","slug":"openai-0dd26ac5","identity":"pypi:openai","label":"OpenAI SDK","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.63.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["docker/requirements.txt"]},{"id":"package:pypi:scikit-learn","slug":"scikit-learn-ab0941d9","identity":"pypi:scikit-learn","label":"scikit-learn","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["1.6.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["docker/requirements.txt"]},{"id":"package:pypi:weaviate-client","slug":"weaviate-client-c34ddc0e","identity":"pypi:weaviate-client","label":"Weaviate Client","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["4.11.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["docker/requirements.txt"]}],"vulnerabilities":[{"id":"GHSA-3644-q5cj-c5c7","slug":"ghsa-3644-q5cj-c5c7-4c578cf2","dossier":false,"summary":"LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning","aliases":["CVE-2026-45134","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"sourceIds":["GHSA-3644-q5cj-c5c7","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"published":"2026-05-13T15:29:30Z","modified":"2026-07-13T16:43:39.736848907Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-3644-q5cj-c5c7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45134"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3644-q5cj-c5c7"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-classic"},{"type":"PACKAGE","url":"https://pypi.org/project/langsmith"}],"versionKeys":["pypi:langchain-classic@1.0.1","pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langsmith@0.6.4"],"packageCount":3,"repositoryCount":3},{"id":"GHSA-45pg-36p6-83v9","slug":"ghsa-45pg-36p6-83v9-9505da12","dossier":false,"summary":"Langchain SQL Injection vulnerability","aliases":["CVE-2024-8309","PYSEC-2024-115","PYSEC-2026-1507"],"sourceIds":["GHSA-45pg-36p6-83v9"],"published":"2024-10-29T15:32:05Z","modified":"2026-07-07T17:57:12.591755527Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8309"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/64c317eba05fbac0c6a6fc5aa192bc0d7130972e"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c2a3021bb0c5f54649d380b42a0684ca5778c255"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-115.yaml"},{"type":"WEB","url":"https://huntr.com/bounties/8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g48c-2wqr-h844","slug":"ghsa-g48c-2wqr-h844-48f35247","dossier":false,"summary":"LangGraph checkpoint loading has unsafe msgpack deserialization","aliases":["CVE-2026-28277","PYSEC-2026-83"],"sourceIds":["GHSA-g48c-2wqr-h844","PYSEC-2026-83"],"published":"2026-03-05T20:16:15.677Z","modified":"2026-06-06T01:00:08.116125988Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-g48c-2wqr-h844"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28277"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langgraph/PYSEC-2026-83.yaml"}],"versionKeys":["pypi:langgraph@0.1.1","pypi:langgraph@0.3.21","pypi:langgraph@1.0.6"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-gr75-jv2w-4656","slug":"ghsa-gr75-jv2w-4656-a5b8c61e","dossier":false,"summary":"LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders","aliases":["CVE-2026-55443","PYSEC-2026-2192","PYSEC-2026-2556"],"sourceIds":["GHSA-gr75-jv2w-4656","PYSEC-2026-2192"],"published":"2026-06-16T15:03:14Z","modified":"2026-07-13T16:43:09.845932020Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-gr75-jv2w-4656"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55443"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"}],"versionKeys":["pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langchain@1.2.6","pypi:langchain@1.3.8"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-pc6w-59fv-rh23","slug":"ghsa-pc6w-59fv-rh23-cab9cb2f","dossier":false,"summary":"Langchain Community Vulnerable to XML External Entity (XXE) Attacks","aliases":["CVE-2025-6984","PYSEC-2026-1515"],"sourceIds":["GHSA-pc6w-59fv-rh23","PYSEC-2026-1515"],"published":"2025-09-04T12:30:42Z","modified":"2026-07-07T17:56:45.822570559Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6984"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain-community/commit/e842452108089524e22c3a2ced851c021884556f"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain-community"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/blob/d79b5813a0b3b243c612b77013768995e46c4337/libs/langchain/langchain/document_loaders/evernote.py#L1-L23"},{"type":"WEB","url":"https://huntr.com/bounties/a6b521cf-258c-41c0-9edb-d8ef976abb2a"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pc6w-59fv-rh23"}],"versionKeys":["pypi:langchain-community@0.2.7","pypi:langchain-community@0.3.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-q25c-c977-4cmh","slug":"ghsa-q25c-c977-4cmh-8e74e348","dossier":false,"summary":"Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever","aliases":["CVE-2024-3095","PYSEC-2026-1516"],"sourceIds":["GHSA-q25c-c977-4cmh","PYSEC-2026-1516"],"published":"2024-06-06T21:30:36Z","modified":"2026-07-07T17:57:27.127785500Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3095"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/24451"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-community%3D%3D0.2.9"},{"type":"WEB","url":"https://huntr.com/bounties/e62d4895-2901-405b-9559-38276b6a5273"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q25c-c977-4cmh"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-r7w7-9xr2-qq2r","slug":"ghsa-r7w7-9xr2-qq2r-7a3a0a91","dossier":false,"summary":"langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding","aliases":["CVE-2026-41488","PYSEC-2026-76"],"sourceIds":["GHSA-r7w7-9xr2-qq2r","PYSEC-2026-76"],"published":"2026-04-16T23:00:12Z","modified":"2026-06-06T01:15:07.912179267Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-r7w7-9xr2-qq2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41488"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain-openai/PYSEC-2026-76.yaml"}],"versionKeys":["pypi:langchain-openai@0.2.8","pypi:langchain-openai@1.1.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-w39p-vh2g-g8g5","slug":"ghsa-w39p-vh2g-g8g5-47880dfe","dossier":false,"summary":"LangGraph SDK has unsafe URL path construction","aliases":["CVE-2026-48776","PYSEC-2026-2194","PYSEC-2026-2575"],"sourceIds":["GHSA-w39p-vh2g-g8g5","PYSEC-2026-2194","PYSEC-2026-2575"],"published":"2026-06-17T10:55:15.113Z","modified":"2026-07-13T16:42:27.619863658Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-w39p-vh2g-g8g5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48776"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/releases/tag/sdk%3D%3D0.3.15"},{"type":"PACKAGE","url":"https://pypi.org/project/langgraph-sdk"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w39p-vh2g-g8g5"}],"versionKeys":["pypi:langgraph-sdk@0.3.3","pypi:langgraph@0.1.1"],"packageCount":2,"repositoryCount":2},{"id":"PYSEC-2024-323","slug":"pysec-2024-323-1dd96856","dossier":false,"summary":null,"aliases":["CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2026-1514"],"sourceIds":["PYSEC-2024-323"],"published":"2024-09-17T12:15:02.977Z","modified":"2026-07-13T07:26:23.643495355Z","checkedAt":"2026-07-20T11:49:05.682Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"}],"versionKeys":["pypi:langchain@0.2.7"],"packageCount":1,"repositoryCount":1}]}}
