vernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-soviaDieses Dossier bewahrt 111 exakte Komponentenvorkommen aus 1 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.
Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.
Projekt-ID + Commit-SHA + exakter EvidenzpfadJede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.
sha256:d444dfad7ad27a1821923a1fc11b3ae40b7e686a1c28dd4b750c45fa1cfa35b8pypi:transformers4.51.026 zurückgegebene OSV-Meldungenpypi:torch2.9.123 zurückgegebene OSV-Meldungenpypi:scikit-learn1.6.11 zurückgegebene OSV-Meldungpypi:sentence-transformers4.0.2pypi:tokenizers0.21.1pypi:opencv-python4.11.0.86pypi:gitpython3.1.4527 zurückgegebene OSV-Meldungenpypi:pillow11.1.020 zurückgegebene OSV-Meldungenpypi:tornado6.5.213 zurückgegebene OSV-Meldungenpypi:urllib32.3.07 zurückgegebene OSV-Meldungenpypi:jinja23.1.64 zurückgegebene OSV-Meldungenpypi:requests2.32.33 zurückgegebene OSV-Meldungenpypi:setuptools78.1.03 zurückgegebene OSV-Meldungenpypi:filelock3.18.02 zurückgegebene OSV-Meldungenpypi:protobuf6.32.12 zurückgegebene OSV-Meldungenpypi:streamlit1.49.12 zurückgegebene OSV-Meldungenpypi:certifi2025.1.311 zurückgegebene OSV-Meldungpypi:click8.2.11 zurückgegebene OSV-Meldungpypi:duckdb1.3.21 zurückgegebene OSV-Meldungpypi:fonttools4.55.81 zurückgegebene OSV-Meldungpypi:geopandas1.0.11 zurückgegebene OSV-Meldungpypi:idna3.101 zurückgegebene OSV-Meldungpypi:pyarrow21.0.01 zurückgegebene OSV-Meldungpypi:pygments2.19.11 zurückgegebene OSV-Meldungpypi:tqdm4.67.11 zurückgegebene OSV-Meldungpypi:altair5.5.0pypi:asttokens3.0.0pypi:attrs25.3.0pypi:blinker1.9.0pypi:branca0.8.1pypi:cachetools6.2.0pypi:charset-normalizer3.4.1pypi:colorama0.4.6pypi:contourpy1.3.1pypi:cycler0.12.1pypi:decorator5.2.1pypi:executing2.2.0pypi:folium0.20.0pypi:fsspec2025.3.2pypi:ftfy6.3.1pypi:gitdb4.0.12pypi:huggingface-hub0.30.1pypi:ipython9.2.0pypi:ipython-pygments-lexers1.1.1pypi:jedi0.19.2pypi:joblib1.4.2pypi:jsonschema4.25.1pypi:jsonschema-specifications2025.9.1pypi:kiwisolver1.4.8pypi:markupsafe3.0.2pypi:matplotlib3.10.0pypi:matplotlib-inline0.1.7pypi:mpmath1.3.0pypi:narwhals2.4.0pypi:networkx3.4.2pypi:numpy2.3.2pypi:nvidia-cublas-cu1212.8.3.14pypi:nvidia-cuda-cupti-cu1212.8.57pypi:nvidia-cuda-nvrtc-cu1212.8.61pypi:nvidia-cuda-runtime-cu1212.8.57pypi:nvidia-cudnn-cu129.7.1.26pypi:nvidia-cufft-cu1211.3.3.41pypi:nvidia-cufile-cu121.13.0.11pypi:nvidia-curand-cu1210.3.9.55pypi:nvidia-cusolver-cu1211.7.2.55pypi:nvidia-cusparse-cu1212.5.7.53pypi:nvidia-cusparselt-cu120.6.3pypi:nvidia-nccl-cu122.26.2pypi:nvidia-nvjitlink-cu1212.8.61pypi:nvidia-nvtx-cu1212.8.55pypi:open-clip-torch2.32.0pypi:packaging24.2pypi:pandas2.2.3pypi:pandas-stubs2.3.2.250827pypi:parso0.8.4pypi:pexpect4.9.0pypi:prompt-toolkit3.0.51pypi:ptyprocess0.7.0pypi:pure-eval0.2.3pypi:pydeck0.9.1pypi:pyogrio0.10.0pypi:pyparsing3.2.1pypi:pyproj3.7.0pypi:python-dateutil2.9.0.post0pypi:pytz2025.1pypi:pyyaml6.0.2pypi:referencing0.36.2pypi:regex2024.11.6pypi:rpds-py0.27.1pypi:safetensors0.5.3pypi:scipy1.15.2pypi:seaborn0.13.2pypi:shapely2.0.7pypi:six1.17.0pypi:smmap5.0.2pypi:stack-data0.6.3pypi:streamlit-folium0.25.1pypi:sympy1.14.0pypi:tenacity9.1.2pypi:threadpoolctl3.6.0pypi:timm1.0.15pypi:toml0.10.2pypi:torchvision0.24.1pypi:traitlets5.14.3pypi:triton3.3.0pypi:types-pytz2025.2.0.20250809pypi:typing-extensions4.13.1pypi:tzdata2025.1pypi:watchdog6.0.0pypi:wcwidth0.2.13pypi:xyzservices2025.4.0Certifi removes GLOBALTRUST root certificate
10. Sept. 2026GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
08. Sept. 2026HuggingFace transformers vulnerable to remote code execution
10. Sept. 2026GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
10. Sept. 2026urllib3 streaming API improperly handles highly compressed data
10. Sept. 2026PyTorch susceptible to local Denial of Service
10. Sept. 2026Transformers is vulnerable to ReDoS attack through its DonutProcessor class
10. Sept. 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10. Sept. 2026GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
10. Sept. 2026GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
10. Sept. 2026GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
10. Sept. 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
10. Sept. 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10. Sept. 2026urllib3 does not control redirects in browsers and Node.js
10. Sept. 2026GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
10. Sept. 2026Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
10. Sept. 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10. Sept. 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10. Sept. 2026GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
10. Sept. 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07. Aug. 2026Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
10. Sept. 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
10. Sept. 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
10. Sept. 2026Pillow has a heap buffer overflow with nested list coordinates
10. Sept. 2026GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
08. Sept. 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
10. Sept. 2026geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure
10. Juni 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
10. Sept. 2026HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
10. Sept. 2026GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
10. Sept. 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
10. Sept. 2026Transformers Regular Expression Denial of Service (ReDoS) vulnerability
13. Aug. 2026GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
10. Sept. 2026fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
10. Sept. 2026GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
08. Sept. 2026Tornado has incomplete validation of cookie attributes
10. Sept. 2026Tornado vulnerable to excessive logging caused by malformed multipart form data
10. Sept. 2026protobuf affected by a JSON recursion depth bypass
10. Sept. 2026Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
13. Juli 2026tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
16. Sept. 2026PyTorch Improper Resource Shutdown or Release vulnerability
10. Sept. 2026GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
08. Sept. 2026protobuf-python has a potential Denial of Service issue
10. Sept. 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
10. Sept. 2026Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
10. Sept. 2026GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
10. Sept. 2026GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
10. Sept. 2026Requests vulnerable to .netrc credentials leak via malicious URLs
10. Sept. 2026Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.
Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.i6eal (2026): URBAN.KI Sovia – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 16. Sept. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-11298/
Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.
Diese Tools ergänzen die aktuelle Auswertung.