← Back to the AI Dependency AtlasExact repository supply-chain dossier

ai-sr-litscreen

OpenBfS/kemf/ai-sr-litscreen
pypi

This dossier retains 9 exact component occurrences from 1 published evidence files at one immutable repository commit.

opencode:124751ccd1f9b7dc9project ID + commit SHA + exact evidence path

Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.

project ID + commit SHA + exact evidence path
9exact component occurrences
9package identities
1evidence file
18OSV records returned
Exact published evidence

Files that resolve this repository’s dependencies

Every file remains tied to the observed commit. A parse error stays visible and never becomes a zero.

Evidence pathrequirements.txt
Format
exact-manifest-pin
Parser state
parsed
Resolved components
9
Open exact source ↗
Observed relations

Package identities at this commit

pypiLangChain Corepypi:langchain-core
1 Occurrence0.3.45
MIT7 OSV records returned
pypiLangChain Communitypypi:langchain-community
1 Occurrence0.3.5
MIT4 OSV records returned
pypiLangChainpypi:langchain
1 Occurrence0.3.7
MIT3 OSV records returned
pypiLangChain · Text Splitterspypi:langchain-text-splitters
1 Occurrence0.3.2
MIT2 OSV records returned
pypiLangChain OpenAIpypi:langchain-openai
1 Occurrence0.3.0
MIT1 OSV record returned
pypiscikit-learnpypi:scikit-learn
1 Occurrence1.3.2
BSD-3-Clause · non-standard1 OSV record returned
pypiOllama SDKpypi:ollama
1 Occurrence0.3.3
MIT
pypiOpenAI SDKpypi:openai
1 Occurrence1.78.1
Apache-2.0
pypiLangChain · Ollamapypi:langchain-ollama
1 Occurrence0.2.0
MIT
OSV

Related OSV records

GHSA-2g6r-c272-w58r

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

3 repositories13 Jul 2026
GHSA-3644-q5cj-c5c7

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

4 repositories13 Jul 2026
GHSA-45pg-36p6-83v9

Langchain SQL Injection vulnerability

1 repository07 Jul 2026
GHSA-5chr-fjjv-38qv

langchain-core allows unauthorized users to read arbitrary files from the host file system

1 repository07 Jul 2026
GHSA-6qv9-48xg-fc7f

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

2 repositories07 Jul 2026
GHSA-926x-3r5x-gfhw

LangChain has incomplete f-string validation in prompt templates

3 repositories13 Jul 2026
GHSA-c67j-w6g6-q2cm

LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs

2 repositories02 Jul 2026
GHSA-fv5p-p927-qmxr

LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

2 repositories06 Jun 2026
GHSA-gr75-jv2w-4656

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

4 repositories07 Aug 2026
GHSA-jw8x-6495-233v

scikit-learn sensitive data leakage vulnerability

1 repository10 Jun 2026
GHSA-m42m-m8cr-8m58

LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing

1 repository07 Jul 2026
GHSA-pc6w-59fv-rh23

Langchain Community Vulnerable to XML External Entity (XXE) Attacks

3 repositories07 Jul 2026
GHSA-pjwx-r37v-7724

LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists

3 repositories13 Jul 2026
GHSA-q25c-c977-4cmh

Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever

1 repository07 Jul 2026
GHSA-qh6h-p6c9-ff54

LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions

3 repositories13 Jul 2026
GHSA-r7w7-9xr2-qq2r

langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding

4 repositories06 Jun 2026
PYSEC-2024-323

Not reported

1 repository13 Jul 2026
Interpretation boundary

Exact identities in, explicit limits out

The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.

Retrieval, parsing, matching and publishing use no generative AI model.

i6eal (2026): ai-sr-litscreen — exact AI dependency evidence dossier, data state 13 Aug 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-12475/

Reading this dossier

Does this repository dossier prove deployment?
No. It documents dependencies published at one observed commit, not a deployed environment.
Why are exact versions required?
OSV and registry metadata can be linked reproducibly only to an observed package@version tuple. The collector never substitutes a newest release for a range.
Does a missing row mean the dependency is absent?
No. It means not observed within the bounded files and repository checkpoint. Incomplete trees and parser failures remain explicit.

Need a permanent dependency evidence trail for another public code cohort?

We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.

Discuss a data projectExplore all tools