← Back to the AI Dependency AtlasExact package identity dossier

Chroma

pypi:chromadb
pypi

This dossier links the stable identity pypi:chromadb to 1 exact observed versions across 1 public repositories.

pypipypi:chromadbecosystem:name + exact version + evidence path

A package identity or provider interface in published code does not prove configuration, an account, procurement, data transfer or an API call.

ecosystem:name + exact version + evidence path
1repository
3exact evidence rows
1exact version
1reported license expression
4OSV records returned
Exact published evidence

Observed exact versions and registry metadata

Publication age and licenses come from deps.dev metadata. They are context—not a maintenance, legal or portability verdict.

Exact version1.0.1231 May 2025
Repositories
1
Occurrences
3
Reported licenses
non-standard
no verified publish attestation reported4 OSV records
Open exact source ↗
Observed relations

Repositories carrying this identity

URBAN.KI UrbanShieldAIvernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-urbanshieldai
1.0.123 Occurrences
Exact published evidence

exact evidence rows

URBAN.KI UrbanShieldAIvernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-urbanshieldai
pypi:chromadb@1.0.12asrp_dir/requirements.txt
direct declarationnot marked as development-only
Open exact source ↗
URBAN.KI UrbanShieldAIvernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-urbanshieldai
pypi:chromadb@1.0.12requirements-file/requirements-docker.txt
direct declarationnot marked as development-only
Open exact source ↗
URBAN.KI UrbanShieldAIvernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-urbanshieldai
pypi:chromadb@1.0.12requirements-file/requirements.txt
direct declarationnot marked as development-only
Open exact source ↗
OSV

Related OSV records

GHSA-2wm9-hf6c-p5cr

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

1 repository10 Sept 2026
GHSA-36p7-vc44-83pf

ChromaDB has a code injection vulnerability

1 repository10 Sept 2026
GHSA-f4j7-r4q5-qw2c

ChromaDB Python project has a pre-authentication code injection vulnerability

1 repository01 Jul 2026
GHSA-xph7-9rjv-w5fr

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

1 repository10 Sept 2026
Interpretation boundary

Exact identities in, explicit limits out

Only exact npm and PyPI tuples are enriched. Reported SPDX expressions are metadata; no compatibility, obligation or legal conclusion is inferred.

Retrieval, parsing, matching and publishing use no generative AI model.

i6eal (2026): Chroma — exact AI dependency evidence dossier, data state 16 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/paket/chromadb-4bcada2e/

Reading this dossier

Does package presence prove that a provider is used?
No. Even a direct interface declaration does not establish configuration, credentials, procurement, data transfer or an API call.
Why are exact versions required?
OSV and registry metadata can be linked reproducibly only to an observed package@version tuple. The collector never substitutes a newest release for a range.
Does a missing row mean the dependency is absent?
No. It means not observed within the bounded files and repository checkpoint. Incomplete trees and parser failures remain explicit.

Need a permanent dependency evidence trail for another public code cohort?

We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.

Discuss a data projectExplore all tools