← Back to the AI Dependency AtlasExact repository supply-chain dossier

URBAN.KI Sovia

vernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-sovia
pypi

This dossier retains 111 exact component occurrences from 1 published evidence files at one immutable repository commit.

opencode:11298b961d043e77aproject ID + commit SHA + exact evidence path

Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.

project ID + commit SHA + exact evidence path
111exact component occurrences
111package identities
1evidence file
142OSV records returned
Exact published evidence

Files that resolve this repository’s dependencies

Every file remains tied to the observed commit. A parse error stays visible and never becomes a zero.

Evidence pathuv.locksha256:d444dfad7ad27a1821923a1fc11b3ae40b7e686a1c28dd4b750c45fa1cfa35b8
Format
uv-lock
Parser state
parsed
Resolved components
111
Open exact source ↗
Observed relations

Package identities at this commit

pypiTransformerspypi:transformers
1 Occurrence4.51.0
Apache-2.026 OSV records returned
pypiPyTorchpypi:torch
1 Occurrence2.9.1
BSD-3-Clause23 OSV records returned
pypiscikit-learnpypi:scikit-learn
1 Occurrence1.6.1
BSD-3-Clause · non-standard1 OSV record returned
pypiSentence Transformerspypi:sentence-transformers
1 Occurrence4.0.2
Apache-2.0
pypiHugging Face Tokenizerspypi:tokenizers
1 Occurrence0.21.1
non-standard
pypiOpenCVpypi:opencv-python
1 Occurrence4.11.0.86
Apache-2.0
pypigitpythonpypi:gitpython
1 Occurrence3.1.45
BSD-3-Clause27 OSV records returned
pypipillowpypi:pillow
1 Occurrence11.1.0
HPND · MIT-CMU20 OSV records returned
pypitornadopypi:tornado
1 Occurrence6.5.2
Apache-2.013 OSV records returned
pypiurllib3pypi:urllib3
1 Occurrence2.3.0
MIT7 OSV records returned
pypijinja2pypi:jinja2
1 Occurrence3.1.6
BSD-3-Clause · non-standard4 OSV records returned
pypirequestspypi:requests
1 Occurrence2.32.3
Apache-2.03 OSV records returned
pypisetuptoolspypi:setuptools
1 Occurrence78.1.0
MIT3 OSV records returned
pypifilelockpypi:filelock
1 Occurrence3.18.0
MIT · Unlicense2 OSV records returned
pypiprotobufpypi:protobuf
1 Occurrence6.32.1
BSD-3-Clause2 OSV records returned
pypistreamlitpypi:streamlit
1 Occurrence1.49.1
Apache-2.02 OSV records returned
pypicertifipypi:certifi
1 Occurrence2025.1.31
MPL-2.01 OSV record returned
pypiclickpypi:click
1 Occurrence8.2.1
BSD-3-Clause · non-standard1 OSV record returned
pypiduckdbpypi:duckdb
1 Occurrence1.3.2
MIT1 OSV record returned
pypifonttoolspypi:fonttools
1 Occurrence4.55.8
MIT1 OSV record returned
pypigeopandaspypi:geopandas
1 Occurrence1.0.1
BSD-3-Clause1 OSV record returned
pypiidnapypi:idna
1 Occurrence3.10
BSD-3-Clause · non-standard1 OSV record returned
pypipyarrowpypi:pyarrow
1 Occurrence21.0.0
Apache-2.0 · non-standard1 OSV record returned
pypipygmentspypi:pygments
1 Occurrence2.19.1
BSD-2-Clause1 OSV record returned
pypitqdmpypi:tqdm
1 Occurrence4.67.1
MIT AND MPL-2.01 OSV record returned
pypialtairpypi:altair
1 Occurrence5.5.0
non-standard
pypiasttokenspypi:asttokens
1 Occurrence3.0.0
Apache-2.0
pypiattrspypi:attrs
1 Occurrence25.3.0
MIT
pypiblinkerpypi:blinker
1 Occurrence1.9.0
MIT
pypibrancapypi:branca
1 Occurrence0.8.1
MIT
pypicachetoolspypi:cachetools
1 Occurrence6.2.0
MIT
pypicharset-normalizerpypi:charset-normalizer
1 Occurrence3.4.1
MIT
pypicoloramapypi:colorama
1 Occurrence0.4.6
non-standard
pypicontourpypypi:contourpy
1 Occurrence1.3.1
non-standard
pypicyclerpypi:cycler
1 Occurrence0.12.1
non-standard
pypidecoratorpypi:decorator
1 Occurrence5.2.1
BSD-2-Clause · non-standard
pypiexecutingpypi:executing
1 Occurrence2.2.0
MIT
pypifoliumpypi:folium
1 Occurrence0.20.0
MIT
pypifsspecpypi:fsspec
1 Occurrence2025.3.2
BSD-3-Clause · non-standard
pypiftfypypi:ftfy
1 Occurrence6.3.1
Apache-2.0
pypigitdbpypi:gitdb
1 Occurrence4.0.12
non-standard
pypihuggingface-hubpypi:huggingface-hub
1 Occurrence0.30.1
Apache-2.0 · non-standard
pypiipythonpypi:ipython
1 Occurrence9.2.0
BSD-3-Clause
pypiipython-pygments-lexerspypi:ipython-pygments-lexers
1 Occurrence1.1.1
non-standard
pypijedipypi:jedi
1 Occurrence0.19.2
MIT
pypijoblibpypi:joblib
1 Occurrence1.4.2
BSD-3-Clause
pypijsonschemapypi:jsonschema
1 Occurrence4.25.1
MIT
pypijsonschema-specificationspypi:jsonschema-specifications
1 Occurrence2025.9.1
MIT
pypikiwisolverpypi:kiwisolver
1 Occurrence1.4.8
non-standard
pypimarkupsafepypi:markupsafe
1 Occurrence3.0.2
BSD-3-Clause · non-standard
pypimatplotlibpypi:matplotlib
1 Occurrence3.10.0
non-standard
pypimatplotlib-inlinepypi:matplotlib-inline
1 Occurrence0.1.7
BSD-3-Clause · non-standard
pypimpmathpypi:mpmath
1 Occurrence1.3.0
non-standard
pypinarwhalspypi:narwhals
1 Occurrence2.4.0
MIT · non-standard
pypinetworkxpypi:networkx
1 Occurrence3.4.2
BSD-3-Clause · non-standard
pypinumpypypi:numpy
1 Occurrence2.3.2
0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib · non-standard
pypinvidia-cublas-cu12pypi:nvidia-cublas-cu12
1 Occurrence12.8.3.14
non-standard
pypinvidia-cuda-cupti-cu12pypi:nvidia-cuda-cupti-cu12
1 Occurrence12.8.57
non-standard
pypinvidia-cuda-nvrtc-cu12pypi:nvidia-cuda-nvrtc-cu12
1 Occurrence12.8.61
non-standard
pypinvidia-cuda-runtime-cu12pypi:nvidia-cuda-runtime-cu12
1 Occurrence12.8.57
non-standard
pypinvidia-cudnn-cu12pypi:nvidia-cudnn-cu12
1 Occurrence9.7.1.26
non-standard
pypinvidia-cufft-cu12pypi:nvidia-cufft-cu12
1 Occurrence11.3.3.41
non-standard
pypinvidia-cufile-cu12pypi:nvidia-cufile-cu12
1 Occurrence1.13.0.11
non-standard
pypinvidia-curand-cu12pypi:nvidia-curand-cu12
1 Occurrence10.3.9.55
non-standard
pypinvidia-cusolver-cu12pypi:nvidia-cusolver-cu12
1 Occurrence11.7.2.55
non-standard
pypinvidia-cusparse-cu12pypi:nvidia-cusparse-cu12
1 Occurrence12.5.7.53
non-standard
pypinvidia-cusparselt-cu12pypi:nvidia-cusparselt-cu12
1 Occurrence0.6.3
non-standard
pypinvidia-nccl-cu12pypi:nvidia-nccl-cu12
1 Occurrence2.26.2
BSD-3-Clause · non-standard
pypinvidia-nvjitlink-cu12pypi:nvidia-nvjitlink-cu12
1 Occurrence12.8.61
non-standard
pypinvidia-nvtx-cu12pypi:nvidia-nvtx-cu12
1 Occurrence12.8.55
Apache-2.0 · non-standard
pypiopen-clip-torchpypi:open-clip-torch
1 Occurrence2.32.0
MIT
pypipackagingpypi:packaging
1 Occurrence24.2
Apache-2.0 OR BSD-2-Clause · non-standard
pypipandaspypi:pandas
1 Occurrence2.2.3
non-standard
pypipandas-stubspypi:pandas-stubs
1 Occurrence2.3.2.250827
BSD-3-Clause
pypiparsopypi:parso
1 Occurrence0.8.4
MIT
pypipexpectpypi:pexpect
1 Occurrence4.9.0
non-standard
pypiprompt-toolkitpypi:prompt-toolkit
1 Occurrence3.0.51
BSD-3-Clause · non-standard
pypiptyprocesspypi:ptyprocess
1 Occurrence0.7.0
ISC
pypipure-evalpypi:pure-eval
1 Occurrence0.2.3
MIT
pypipydeckpypi:pydeck
1 Occurrence0.9.1
Apache-2.0
pypipyogriopypi:pyogrio
1 Occurrence0.10.0
non-standard
pypipyparsingpypi:pyparsing
1 Occurrence3.2.1
MIT
pypipyprojpypi:pyproj
1 Occurrence3.7.0
MIT
pypipython-dateutilpypi:python-dateutil
1 Occurrence2.9.0.post0
non-standard
pypipytzpypi:pytz
1 Occurrence2025.1
MIT
pypipyyamlpypi:pyyaml
1 Occurrence6.0.2
MIT
pypireferencingpypi:referencing
1 Occurrence0.36.2
MIT
pypiregexpypi:regex
1 Occurrence2024.11.6
Apache-2.0 AND CNRI-Python · non-standard
pypirpds-pypypi:rpds-py
1 Occurrence0.27.1
MIT
pypisafetensorspypi:safetensors
1 Occurrence0.5.3
non-standard
pypiscipypypi:scipy
1 Occurrence1.15.2
non-standard
pypiseabornpypi:seaborn
1 Occurrence0.13.2
non-standard
pypishapelypypi:shapely
1 Occurrence2.0.7
BSD-3-Clause
pypisixpypi:six
1 Occurrence1.17.0
MIT
pypismmappypi:smmap
1 Occurrence5.0.2
BSD-3-Clause
pypistack-datapypi:stack-data
1 Occurrence0.6.3
MIT
pypistreamlit-foliumpypi:streamlit-folium
1 Occurrence0.25.1
Not reported
pypisympypypi:sympy
1 Occurrence1.14.0
non-standard
pypitenacitypypi:tenacity
1 Occurrence9.1.2
Apache-2.0
pypithreadpoolctlpypi:threadpoolctl
1 Occurrence3.6.0
BSD-3-Clause
pypitimmpypi:timm
1 Occurrence1.0.15
Apache-2.0
pypitomlpypi:toml
1 Occurrence0.10.2
MIT
pypitorchvisionpypi:torchvision
1 Occurrence0.24.1
non-standard
pypitraitletspypi:traitlets
1 Occurrence5.14.3
non-standard
pypitritonpypi:triton
1 Occurrence3.3.0
MIT
pypitypes-pytzpypi:types-pytz
1 Occurrence2025.2.0.20250809
Apache-2.0
pypityping-extensionspypi:typing-extensions
1 Occurrence4.13.1
PSF-2.0 · non-standard
pypitzdatapypi:tzdata
1 Occurrence2025.1
Apache-2.0
pypiwatchdogpypi:watchdog
1 Occurrence6.0.0
Apache-2.0
pypiwcwidthpypi:wcwidth
1 Occurrence0.2.13
MIT
pypixyzservicespypi:xyzservices
1 Occurrence2025.4.0
BSD-3-Clause
OSV

Related OSV records

GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

1 repository10 Sept 2026
GHSA-284h-m62q-gf8w

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

6 repositories08 Sept 2026
GHSA-29pf-2h5f-8g72

HuggingFace transformers vulnerable to remote code execution

11 repositories10 Sept 2026
GHSA-2f96-g7mh-g2hx

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

6 repositories10 Sept 2026
GHSA-2xpw-w6gg-jr37

urllib3 streaming API improperly handles highly compressed data

16 repositories10 Sept 2026
GHSA-3749-ghw9-m3mg

PyTorch susceptible to local Denial of Service

3 repositories10 Sept 2026
GHSA-37mw-44qp-f5jm

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

3 repositories10 Sept 2026
GHSA-38jv-5279-wg99

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

16 repositories10 Sept 2026
GHSA-3f7w-8rr8-f37f

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

6 repositories10 Sept 2026
GHSA-3rp5-jjmw-4wv2

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

6 repositories10 Sept 2026
GHSA-3wxw-xv34-2frg

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

6 repositories10 Sept 2026
GHSA-3x9g-8vmp-wqvf

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

9 repositories10 Sept 2026
GHSA-45hq-cxwh-f6vc

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

17 repositories10 Sept 2026
GHSA-48p4-8xcf-vxj5

urllib3 does not control redirects in browsers and Node.js

8 repositories10 Sept 2026
GHSA-4gmw-gg2m-w46p

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

6 repositories10 Sept 2026
GHSA-4w7r-h757-3r74

Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer

4 repositories10 Sept 2026
GHSA-4x4j-2g7c-83w6

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

17 repositories10 Sept 2026
GHSA-5239-wwwm-4pmq

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

15 repositories10 Sept 2026
GHSA-539m-9xh6-q6rr

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

6 repositories10 Sept 2026
GHSA-53q9-r3pm-6pq6

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

1 repository07 Aug 2026
GHSA-59p9-h35m-wg4g

Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer

4 repositories10 Sept 2026
GHSA-5rjg-fvgr-3xxf

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

4 repositories10 Sept 2026
GHSA-5x94-69rx-g8h2

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

17 repositories10 Sept 2026
GHSA-5xmw-vc9v-4wf2

Pillow has a heap buffer overflow with nested list coordinates

12 repositories10 Sept 2026
GHSA-5xxx-qhh7-9287

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

6 repositories08 Sept 2026
GHSA-62p4-gmf7-7g93

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

17 repositories10 Sept 2026
GHSA-6497-prx7-gpmq

geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure

2 repositories10 Jun 2026
GHSA-65pc-fj4g-8rjx

Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix

21 repositories10 Sept 2026
GHSA-69w3-r845-3855

HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class

11 repositories10 Sept 2026
GHSA-6p8h-3wgx-97gf

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

6 repositories10 Sept 2026
GHSA-6r8x-57c9-28j4

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

17 repositories10 Sept 2026
GHSA-6rvg-6v2m-4j46

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

1 repository13 Aug 2026
GHSA-7545-fcxq-7j24

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

6 repositories10 Sept 2026
GHSA-768j-98cg-p3fv

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

7 repositories10 Sept 2026
GHSA-7833-fr7j-v32q

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

6 repositories08 Sept 2026
GHSA-78cv-mqj4-43f7

Tornado has incomplete validation of cookie attributes

9 repositories10 Sept 2026
GHSA-7cx3-6m66-7c5m

Tornado vulnerable to excessive logging caused by malformed multipart form data

2 repositories10 Sept 2026
GHSA-7gcm-g887-7qv7

protobuf affected by a JSON recursion depth bypass

13 repositories10 Sept 2026
GHSA-7p48-42j8-8846

Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)

3 repositories13 Jul 2026
GHSA-8423-8fgw-73vq

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

11 repositories16 Sept 2026
GHSA-887c-mr87-cxwp

PyTorch Improper Resource Shutdown or Release vulnerability

8 repositories10 Sept 2026
GHSA-8mcc-hrx5-hvxc

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

6 repositories08 Sept 2026
GHSA-8qvm-5x2c-j2w7

protobuf-python has a potential Denial of Service issue

3 repositories10 Sept 2026
GHSA-8v84-f9pq-wr9x

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

17 repositories10 Sept 2026
GHSA-9356-575x-2w9m

Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability

4 repositories10 Sept 2026
GHSA-94p4-4cq8-9g67

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

6 repositories10 Sept 2026
GHSA-956x-8gvw-wg5v

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

6 repositories10 Sept 2026
GHSA-9hjg-9r4m-mvj7

Requests vulnerable to .netrc credentials leak via malicious URLs

8 repositories10 Sept 2026
Interpretation boundary

Exact identities in, explicit limits out

The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.

Retrieval, parsing, matching and publishing use no generative AI model.

i6eal (2026): URBAN.KI Sovia — exact AI dependency evidence dossier, data state 16 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-11298/

Reading this dossier

Does this repository dossier prove deployment?
No. It documents dependencies published at one observed commit, not a deployed environment.
Why are exact versions required?
OSV and registry metadata can be linked reproducibly only to an observed package@version tuple. The collector never substitutes a newest release for a range.
Does a missing row mean the dependency is absent?
No. It means not observed within the bounded files and repository checkpoint. Incomplete trees and parser failures remain explicit.

Need a permanent dependency evidence trail for another public code cohort?

We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.

Discuss a data projectExplore all tools