← Zurück zum KI-AbhängigkeitsatlasExaktes Repository-Lieferkettendossier

URBAN.KI Sovia

vernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-sovia
pypi

Dieses Dossier bewahrt 111 exakte Komponentenvorkommen aus 1 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.

opencode:11298b961d043e77aProjekt-ID + Commit-SHA + exakter Evidenzpfad

Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.

Projekt-ID + Commit-SHA + exakter Evidenzpfad
111exakte Komponentenvorkommen
111Paketidentitäten
1Evidenzdatei
142zurückgegebene OSV-Meldungen
Exakte veröffentlichte Evidenz

Dateien, die Abhängigkeiten dieses Repositories auflösen

Jede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.

Evidenzpfaduv.locksha256:d444dfad7ad27a1821923a1fc11b3ae40b7e686a1c28dd4b750c45fa1cfa35b8
Format
uv-lock
Parserstatus
parsed
Aufgelöste Komponenten
111
Exakte Quelle öffnen ↗
Beobachtete Beziehungen

Paketidentitäten an diesem Commit

pypiTransformerspypi:transformers
1 Vorkommen4.51.0
Apache-2.026 zurückgegebene OSV-Meldungen
pypiPyTorchpypi:torch
1 Vorkommen2.9.1
BSD-3-Clause23 zurückgegebene OSV-Meldungen
pypiscikit-learnpypi:scikit-learn
1 Vorkommen1.6.1
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
pypiSentence Transformerspypi:sentence-transformers
1 Vorkommen4.0.2
Apache-2.0
pypiHugging Face Tokenizerspypi:tokenizers
1 Vorkommen0.21.1
non-standard
pypiOpenCVpypi:opencv-python
1 Vorkommen4.11.0.86
Apache-2.0
pypigitpythonpypi:gitpython
1 Vorkommen3.1.45
BSD-3-Clause27 zurückgegebene OSV-Meldungen
pypipillowpypi:pillow
1 Vorkommen11.1.0
HPND · MIT-CMU20 zurückgegebene OSV-Meldungen
pypitornadopypi:tornado
1 Vorkommen6.5.2
Apache-2.013 zurückgegebene OSV-Meldungen
pypiurllib3pypi:urllib3
1 Vorkommen2.3.0
MIT7 zurückgegebene OSV-Meldungen
pypijinja2pypi:jinja2
1 Vorkommen3.1.6
BSD-3-Clause · non-standard4 zurückgegebene OSV-Meldungen
pypirequestspypi:requests
1 Vorkommen2.32.3
Apache-2.03 zurückgegebene OSV-Meldungen
pypisetuptoolspypi:setuptools
1 Vorkommen78.1.0
MIT3 zurückgegebene OSV-Meldungen
pypifilelockpypi:filelock
1 Vorkommen3.18.0
MIT · Unlicense2 zurückgegebene OSV-Meldungen
pypiprotobufpypi:protobuf
1 Vorkommen6.32.1
BSD-3-Clause2 zurückgegebene OSV-Meldungen
pypistreamlitpypi:streamlit
1 Vorkommen1.49.1
Apache-2.02 zurückgegebene OSV-Meldungen
pypicertifipypi:certifi
1 Vorkommen2025.1.31
MPL-2.01 zurückgegebene OSV-Meldung
pypiclickpypi:click
1 Vorkommen8.2.1
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
pypiduckdbpypi:duckdb
1 Vorkommen1.3.2
MIT1 zurückgegebene OSV-Meldung
pypifonttoolspypi:fonttools
1 Vorkommen4.55.8
MIT1 zurückgegebene OSV-Meldung
pypigeopandaspypi:geopandas
1 Vorkommen1.0.1
BSD-3-Clause1 zurückgegebene OSV-Meldung
pypiidnapypi:idna
1 Vorkommen3.10
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
pypipyarrowpypi:pyarrow
1 Vorkommen21.0.0
Apache-2.0 · non-standard1 zurückgegebene OSV-Meldung
pypipygmentspypi:pygments
1 Vorkommen2.19.1
BSD-2-Clause1 zurückgegebene OSV-Meldung
pypitqdmpypi:tqdm
1 Vorkommen4.67.1
MIT AND MPL-2.01 zurückgegebene OSV-Meldung
pypialtairpypi:altair
1 Vorkommen5.5.0
non-standard
pypiasttokenspypi:asttokens
1 Vorkommen3.0.0
Apache-2.0
pypiattrspypi:attrs
1 Vorkommen25.3.0
MIT
pypiblinkerpypi:blinker
1 Vorkommen1.9.0
MIT
pypibrancapypi:branca
1 Vorkommen0.8.1
MIT
pypicachetoolspypi:cachetools
1 Vorkommen6.2.0
MIT
pypicharset-normalizerpypi:charset-normalizer
1 Vorkommen3.4.1
MIT
pypicoloramapypi:colorama
1 Vorkommen0.4.6
non-standard
pypicontourpypypi:contourpy
1 Vorkommen1.3.1
non-standard
pypicyclerpypi:cycler
1 Vorkommen0.12.1
non-standard
pypidecoratorpypi:decorator
1 Vorkommen5.2.1
BSD-2-Clause · non-standard
pypiexecutingpypi:executing
1 Vorkommen2.2.0
MIT
pypifoliumpypi:folium
1 Vorkommen0.20.0
MIT
pypifsspecpypi:fsspec
1 Vorkommen2025.3.2
BSD-3-Clause · non-standard
pypiftfypypi:ftfy
1 Vorkommen6.3.1
Apache-2.0
pypigitdbpypi:gitdb
1 Vorkommen4.0.12
non-standard
pypihuggingface-hubpypi:huggingface-hub
1 Vorkommen0.30.1
Apache-2.0 · non-standard
pypiipythonpypi:ipython
1 Vorkommen9.2.0
BSD-3-Clause
pypiipython-pygments-lexerspypi:ipython-pygments-lexers
1 Vorkommen1.1.1
non-standard
pypijedipypi:jedi
1 Vorkommen0.19.2
MIT
pypijoblibpypi:joblib
1 Vorkommen1.4.2
BSD-3-Clause
pypijsonschemapypi:jsonschema
1 Vorkommen4.25.1
MIT
pypijsonschema-specificationspypi:jsonschema-specifications
1 Vorkommen2025.9.1
MIT
pypikiwisolverpypi:kiwisolver
1 Vorkommen1.4.8
non-standard
pypimarkupsafepypi:markupsafe
1 Vorkommen3.0.2
BSD-3-Clause · non-standard
pypimatplotlibpypi:matplotlib
1 Vorkommen3.10.0
non-standard
pypimatplotlib-inlinepypi:matplotlib-inline
1 Vorkommen0.1.7
BSD-3-Clause · non-standard
pypimpmathpypi:mpmath
1 Vorkommen1.3.0
non-standard
pypinarwhalspypi:narwhals
1 Vorkommen2.4.0
MIT · non-standard
pypinetworkxpypi:networkx
1 Vorkommen3.4.2
BSD-3-Clause · non-standard
pypinumpypypi:numpy
1 Vorkommen2.3.2
0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib · non-standard
pypinvidia-cublas-cu12pypi:nvidia-cublas-cu12
1 Vorkommen12.8.3.14
non-standard
pypinvidia-cuda-cupti-cu12pypi:nvidia-cuda-cupti-cu12
1 Vorkommen12.8.57
non-standard
pypinvidia-cuda-nvrtc-cu12pypi:nvidia-cuda-nvrtc-cu12
1 Vorkommen12.8.61
non-standard
pypinvidia-cuda-runtime-cu12pypi:nvidia-cuda-runtime-cu12
1 Vorkommen12.8.57
non-standard
pypinvidia-cudnn-cu12pypi:nvidia-cudnn-cu12
1 Vorkommen9.7.1.26
non-standard
pypinvidia-cufft-cu12pypi:nvidia-cufft-cu12
1 Vorkommen11.3.3.41
non-standard
pypinvidia-cufile-cu12pypi:nvidia-cufile-cu12
1 Vorkommen1.13.0.11
non-standard
pypinvidia-curand-cu12pypi:nvidia-curand-cu12
1 Vorkommen10.3.9.55
non-standard
pypinvidia-cusolver-cu12pypi:nvidia-cusolver-cu12
1 Vorkommen11.7.2.55
non-standard
pypinvidia-cusparse-cu12pypi:nvidia-cusparse-cu12
1 Vorkommen12.5.7.53
non-standard
pypinvidia-cusparselt-cu12pypi:nvidia-cusparselt-cu12
1 Vorkommen0.6.3
non-standard
pypinvidia-nccl-cu12pypi:nvidia-nccl-cu12
1 Vorkommen2.26.2
BSD-3-Clause · non-standard
pypinvidia-nvjitlink-cu12pypi:nvidia-nvjitlink-cu12
1 Vorkommen12.8.61
non-standard
pypinvidia-nvtx-cu12pypi:nvidia-nvtx-cu12
1 Vorkommen12.8.55
Apache-2.0 · non-standard
pypiopen-clip-torchpypi:open-clip-torch
1 Vorkommen2.32.0
MIT
pypipackagingpypi:packaging
1 Vorkommen24.2
Apache-2.0 OR BSD-2-Clause · non-standard
pypipandaspypi:pandas
1 Vorkommen2.2.3
non-standard
pypipandas-stubspypi:pandas-stubs
1 Vorkommen2.3.2.250827
BSD-3-Clause
pypiparsopypi:parso
1 Vorkommen0.8.4
MIT
pypipexpectpypi:pexpect
1 Vorkommen4.9.0
non-standard
pypiprompt-toolkitpypi:prompt-toolkit
1 Vorkommen3.0.51
BSD-3-Clause · non-standard
pypiptyprocesspypi:ptyprocess
1 Vorkommen0.7.0
ISC
pypipure-evalpypi:pure-eval
1 Vorkommen0.2.3
MIT
pypipydeckpypi:pydeck
1 Vorkommen0.9.1
Apache-2.0
pypipyogriopypi:pyogrio
1 Vorkommen0.10.0
non-standard
pypipyparsingpypi:pyparsing
1 Vorkommen3.2.1
MIT
pypipyprojpypi:pyproj
1 Vorkommen3.7.0
MIT
pypipython-dateutilpypi:python-dateutil
1 Vorkommen2.9.0.post0
non-standard
pypipytzpypi:pytz
1 Vorkommen2025.1
MIT
pypipyyamlpypi:pyyaml
1 Vorkommen6.0.2
MIT
pypireferencingpypi:referencing
1 Vorkommen0.36.2
MIT
pypiregexpypi:regex
1 Vorkommen2024.11.6
Apache-2.0 AND CNRI-Python · non-standard
pypirpds-pypypi:rpds-py
1 Vorkommen0.27.1
MIT
pypisafetensorspypi:safetensors
1 Vorkommen0.5.3
non-standard
pypiscipypypi:scipy
1 Vorkommen1.15.2
non-standard
pypiseabornpypi:seaborn
1 Vorkommen0.13.2
non-standard
pypishapelypypi:shapely
1 Vorkommen2.0.7
BSD-3-Clause
pypisixpypi:six
1 Vorkommen1.17.0
MIT
pypismmappypi:smmap
1 Vorkommen5.0.2
BSD-3-Clause
pypistack-datapypi:stack-data
1 Vorkommen0.6.3
MIT
pypistreamlit-foliumpypi:streamlit-folium
1 Vorkommen0.25.1
Nicht gemeldet
pypisympypypi:sympy
1 Vorkommen1.14.0
non-standard
pypitenacitypypi:tenacity
1 Vorkommen9.1.2
Apache-2.0
pypithreadpoolctlpypi:threadpoolctl
1 Vorkommen3.6.0
BSD-3-Clause
pypitimmpypi:timm
1 Vorkommen1.0.15
Apache-2.0
pypitomlpypi:toml
1 Vorkommen0.10.2
MIT
pypitorchvisionpypi:torchvision
1 Vorkommen0.24.1
non-standard
pypitraitletspypi:traitlets
1 Vorkommen5.14.3
non-standard
pypitritonpypi:triton
1 Vorkommen3.3.0
MIT
pypitypes-pytzpypi:types-pytz
1 Vorkommen2025.2.0.20250809
Apache-2.0
pypityping-extensionspypi:typing-extensions
1 Vorkommen4.13.1
PSF-2.0 · non-standard
pypitzdatapypi:tzdata
1 Vorkommen2025.1
Apache-2.0
pypiwatchdogpypi:watchdog
1 Vorkommen6.0.0
Apache-2.0
pypiwcwidthpypi:wcwidth
1 Vorkommen0.2.13
MIT
pypixyzservicespypi:xyzservices
1 Vorkommen2025.4.0
BSD-3-Clause
OSV

Zugehörige OSV-Meldungen

GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

1 Repository10. Sept. 2026
GHSA-284h-m62q-gf8w

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

6 Repositories08. Sept. 2026
GHSA-29pf-2h5f-8g72

HuggingFace transformers vulnerable to remote code execution

11 Repositories10. Sept. 2026
GHSA-2f96-g7mh-g2hx

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

6 Repositories10. Sept. 2026
GHSA-2xpw-w6gg-jr37

urllib3 streaming API improperly handles highly compressed data

16 Repositories10. Sept. 2026
GHSA-3749-ghw9-m3mg

PyTorch susceptible to local Denial of Service

3 Repositories10. Sept. 2026
GHSA-37mw-44qp-f5jm

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

3 Repositories10. Sept. 2026
GHSA-38jv-5279-wg99

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

16 Repositories10. Sept. 2026
GHSA-3f7w-8rr8-f37f

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

6 Repositories10. Sept. 2026
GHSA-3rp5-jjmw-4wv2

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

6 Repositories10. Sept. 2026
GHSA-3wxw-xv34-2frg

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

6 Repositories10. Sept. 2026
GHSA-3x9g-8vmp-wqvf

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

9 Repositories10. Sept. 2026
GHSA-45hq-cxwh-f6vc

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

17 Repositories10. Sept. 2026
GHSA-48p4-8xcf-vxj5

urllib3 does not control redirects in browsers and Node.js

8 Repositories10. Sept. 2026
GHSA-4gmw-gg2m-w46p

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

6 Repositories10. Sept. 2026
GHSA-4w7r-h757-3r74

Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer

4 Repositories10. Sept. 2026
GHSA-4x4j-2g7c-83w6

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

17 Repositories10. Sept. 2026
GHSA-5239-wwwm-4pmq

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

15 Repositories10. Sept. 2026
GHSA-539m-9xh6-q6rr

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

6 Repositories10. Sept. 2026
GHSA-53q9-r3pm-6pq6

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

1 Repository07. Aug. 2026
GHSA-59p9-h35m-wg4g

Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer

4 Repositories10. Sept. 2026
GHSA-5rjg-fvgr-3xxf

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

4 Repositories10. Sept. 2026
GHSA-5x94-69rx-g8h2

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

17 Repositories10. Sept. 2026
GHSA-5xmw-vc9v-4wf2

Pillow has a heap buffer overflow with nested list coordinates

12 Repositories10. Sept. 2026
GHSA-5xxx-qhh7-9287

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

6 Repositories08. Sept. 2026
GHSA-62p4-gmf7-7g93

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

17 Repositories10. Sept. 2026
GHSA-6497-prx7-gpmq

geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure

2 Repositories10. Juni 2026
GHSA-65pc-fj4g-8rjx

Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix

21 Repositories10. Sept. 2026
GHSA-69w3-r845-3855

HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class

11 Repositories10. Sept. 2026
GHSA-6p8h-3wgx-97gf

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

6 Repositories10. Sept. 2026
GHSA-6r8x-57c9-28j4

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

17 Repositories10. Sept. 2026
GHSA-6rvg-6v2m-4j46

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

1 Repository13. Aug. 2026
GHSA-7545-fcxq-7j24

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

6 Repositories10. Sept. 2026
GHSA-768j-98cg-p3fv

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

7 Repositories10. Sept. 2026
GHSA-7833-fr7j-v32q

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

6 Repositories08. Sept. 2026
GHSA-78cv-mqj4-43f7

Tornado has incomplete validation of cookie attributes

9 Repositories10. Sept. 2026
GHSA-7cx3-6m66-7c5m

Tornado vulnerable to excessive logging caused by malformed multipart form data

2 Repositories10. Sept. 2026
GHSA-7gcm-g887-7qv7

protobuf affected by a JSON recursion depth bypass

13 Repositories10. Sept. 2026
GHSA-7p48-42j8-8846

Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)

3 Repositories13. Juli 2026
GHSA-8423-8fgw-73vq

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

11 Repositories16. Sept. 2026
GHSA-887c-mr87-cxwp

PyTorch Improper Resource Shutdown or Release vulnerability

8 Repositories10. Sept. 2026
GHSA-8mcc-hrx5-hvxc

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

6 Repositories08. Sept. 2026
GHSA-8qvm-5x2c-j2w7

protobuf-python has a potential Denial of Service issue

3 Repositories10. Sept. 2026
GHSA-8v84-f9pq-wr9x

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

17 Repositories10. Sept. 2026
GHSA-9356-575x-2w9m

Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability

4 Repositories10. Sept. 2026
GHSA-94p4-4cq8-9g67

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

6 Repositories10. Sept. 2026
GHSA-956x-8gvw-wg5v

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

6 Repositories10. Sept. 2026
GHSA-9hjg-9r4m-mvj7

Requests vulnerable to .netrc credentials leak via malicious URLs

8 Repositories10. Sept. 2026
Interpretationsgrenze

Exakte Identitäten hinein, klare Grenzen hinaus

Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.

Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.

i6eal (2026): URBAN.KI Sovia – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 16. Sept. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-11298/

So liest du dieses Dossier

Belegt dieses Repository-Dossier einen Betrieb?
Nein. Es dokumentiert veröffentlichte Abhängigkeiten an einem beobachteten Commit – keine eingesetzte Umgebung.
Warum sind exakte Versionen erforderlich?
OSV- und Registermetadaten lassen sich nur mit einem beobachteten paket@version-Tupel reproduzierbar verknüpfen. Der Collector ersetzt einen Versionsbereich nie durch das neueste Release.
Bedeutet eine fehlende Zeile, dass die Abhängigkeit nicht existiert?
Nein. Sie bedeutet nur „in den begrenzten Dateien und am Repository-Prüfpunkt nicht beobachtet“. Unvollständige Bäume und Parserfehler bleiben ausdrücklich sichtbar.

Du brauchst einen dauerhaften Abhängigkeitsevidenzpfad für eine andere öffentliche Code-Kohorte?

Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.

Datenprojekt besprechenAlle Tools ansehen