← Back to the AI Dependency AtlasExact repository supply-chain dossier

ki_edu-alt_texts

ife/ki_edu-alt_texts
pypi

This dossier retains 5 exact component occurrences from 1 published evidence files at one immutable repository commit.

opencode:128046083d3dc84e4project ID + commit SHA + exact evidence path

Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.

project ID + commit SHA + exact evidence path
5exact component occurrences
5package identities
1evidence file
23OSV records returned
Exact published evidence

Files that resolve this repository’s dependencies

Every file remains tied to the observed commit. A parse error stays visible and never becomes a zero.

Evidence pathrequirements.txt
Format
exact-manifest-pin
Parser state
parsed
Resolved components
5
Open exact source ↗
Observed relations

Package identities at this commit

pypiPyTorchpypi:torch
1 Occurrence2.12.1
BSD-3-Clause23 OSV records returned
pypiOpenAI SDKpypi:openai
1 Occurrence2.44.0
Apache-2.0
pypiOpenCVpypi:opencv-python
1 Occurrence5.0.0.93
Apache-2.0
pypitiktokenpypi:tiktoken
1 Occurrence0.13.0
non-standard
pypiUltralyticspypi:ultralytics
1 Occurrence8.4.84
AGPL-3.0
OSV

Related OSV records

GHSA-3749-ghw9-m3mg

PyTorch susceptible to local Denial of Service

3 repositories10 Jun 2026
GHSA-53q9-r3pm-6pq6

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

1 repository07 Aug 2026
GHSA-887c-mr87-cxwp

PyTorch Improper Resource Shutdown or Release vulnerability

7 repositories07 Aug 2026
GHSA-c678-jfcj-6jmf

PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument

2 repositories09 Jun 2026
GHSA-f4hp-rmr7-r7v8

PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function

2 repositories10 Jun 2026
GHSA-qfhq-4f3w-5fph

PyTorch is vulnerable to memory corruption through its torch.lstm_cell function

9 repositories10 Jun 2026
GHSA-rrmf-rvhw-rf47

PyTorch is vulnerable to memory corruption through its torch.jit.script function

11 repositories17 Jul 2026
GHSA-vgrw-7cvw-pwgx

PyTorch is vulnerable to memory corruption through its unpack_sequence function

8 repositories10 Jun 2026
GHSA-x3gm-94wq-g975

PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module

2 repositories10 Jun 2026
PYSEC-2025-198

Not reported

2 repositories20 May 2026
PYSEC-2025-199

Not reported

1 repository20 May 2026
PYSEC-2025-200

Not reported

1 repository20 May 2026
PYSEC-2025-201

Not reported

1 repository20 May 2026
PYSEC-2025-202

Not reported

1 repository20 May 2026
PYSEC-2025-203

Not reported

8 repositories20 May 2026
PYSEC-2025-204

Not reported

8 repositories20 May 2026
PYSEC-2025-205

Not reported

3 repositories20 May 2026
PYSEC-2025-206

Not reported

8 repositories20 May 2026
PYSEC-2025-207

Not reported

3 repositories20 May 2026
PYSEC-2025-208

Not reported

3 repositories20 May 2026
PYSEC-2025-209

Not reported

3 repositories20 May 2026
PYSEC-2026-139

Not reported

10 repositories21 May 2026
PYSEC-2026-2286

Not reported

9 repositories13 Jul 2026
Interpretation boundary

Exact identities in, explicit limits out

The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.

Retrieval, parsing, matching and publishing use no generative AI model.

i6eal (2026): ki_edu-alt_texts — exact AI dependency evidence dossier, data state 01 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-12804/

Reading this dossier

Does this repository dossier prove deployment?
No. It documents dependencies published at one observed commit, not a deployed environment.
Why are exact versions required?
OSV and registry metadata can be linked reproducibly only to an observed package@version tuple. The collector never substitutes a newest release for a range.
Does a missing row mean the dependency is absent?
No. It means not observed within the bounded files and repository checkpoint. Incomplete trees and parser failures remain explicit.

Need a permanent dependency evidence trail for another public code cohort?

We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.

Discuss a data projectExplore all tools