← Back to the AI Dependency AtlasExact repository supply-chain dossier

URBAN.KI AIMOS

vernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-aimos
pypi

This dossier retains 3 exact component occurrences from 1 published evidence files at one immutable repository commit.

opencode:112970b637c00c16cproject ID + commit SHA + exact evidence path

Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.

project ID + commit SHA + exact evidence path
3exact component occurrences
3package identities
1evidence file
1OSV record returned
Exact published evidence

Files that resolve this repository’s dependencies

Every file remains tied to the observed commit. A parse error stays visible and never becomes a zero.

Evidence pathrequirements.txt
Format
exact-manifest-pin
Parser state
parsed
Resolved components
3
Open exact source ↗
Observed relations

Package identities at this commit

pypiscikit-learnpypi:scikit-learn
1 Occurrence1.7.1
BSD-3-Clause · non-standard1 OSV record returned
pypiLightGBMpypi:lightgbm
1 Occurrence4.6.0
non-standard
pypiXGBoostpypi:xgboost
1 Occurrence3.0.3
Apache-2.0
OSV

Related OSV records

GHSA-jw8x-6495-233v

scikit-learn sensitive data leakage vulnerability

1 repository10 Sept 2026
Interpretation boundary

Exact identities in, explicit limits out

The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.

Retrieval, parsing, matching and publishing use no generative AI model.

i6eal (2026): URBAN.KI AIMOS — exact AI dependency evidence dossier, data state 16 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-11297/

Reading this dossier

Does this repository dossier prove deployment?
No. It documents dependencies published at one observed commit, not a deployed environment.
Why are exact versions required?
OSV and registry metadata can be linked reproducibly only to an observed package@version tuple. The collector never substitutes a newest release for a range.
Does a missing row mean the dependency is absent?
No. It means not observed within the bounded files and repository checkpoint. Incomplete trees and parser failures remain explicit.

Need a permanent dependency evidence trail for another public code cohort?

We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.

Discuss a data projectExplore all tools