sh/digitalhub-sh/landesprogramm-offene-innovationen/ki-bauleitplaene/smartplanai-anwendungThis dossier retains 318 exact component occurrences from 3 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:d6cf494bd944eff796a59b32b36c8214816e3be6639d5c2ea67893310aa39322sha256:834ae2be07a53839d9a28b3e1f69e45e947515a00364ef07871b6fc47c379933sha256:aeab690097e8e006cb4680cb53d452b805b943ab2091762607ff4d493cc71549pypi:opencv-python4.12.0.88 · 4.13.0.92pypi:gitpython3.1.45 · 3.1.4629 OSV records returnedpypi:pillow11.3.0 · 12.1.120 OSV records returnedpypi:tornado6.5.2 · 6.5.513 OSV records returnedpypi:urllib32.5.0 · 2.6.37 OSV records returnednpm:vite6.3.57 OSV records returnedpypi:jinja23.1.64 OSV records returnednpm:postcss8.5.64 OSV records returnedpypi:ujson5.12.04 OSV records returnednpm:nanoid3.3.113 OSV records returnedpypi:requests2.32.5 · 2.33.13 OSV records returnedpypi:setuptools80.9.0 · 82.0.13 OSV records returnedpypi:anyio4.13.02 OSV records returnedpypi:filelock3.19.1 · 3.25.22 OSV records returnednpm:picomatch4.0.32 OSV records returnedpypi:protobuf6.32.0 · 6.33.62 OSV records returnedpypi:streamlit1.49.0 · 1.55.02 OSV records returnedpypi:certifi2025.8.3 · 2026.2.251 OSV record returnedpypi:click8.1.8 · 8.3.11 OSV record returnednpm:esbuild0.25.81 OSV record returnedpypi:fonttools4.62.11 OSV record returnedpypi:geopandas1.1.31 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:idna3.10 · 3.111 OSV record returnedpypi:pyarrow21.0.0 · 23.0.11 OSV record returnedpypi:pycryptodome3.23.01 OSV record returnedpypi:pygments2.19.2 · 2.20.01 OSV record returnedpypi:pytest8.3.21 OSV record returnednpm:rollup4.46.11 OSV record returnedpypi:tqdm4.67.31 OSV record returnedpypi:virtualenv20.34.01 OSV record returnednpm:@esbuild/aix-ppc640.25.8npm:@esbuild/android-arm0.25.8npm:@esbuild/android-arm640.25.8npm:@esbuild/android-x640.25.8npm:@esbuild/darwin-arm640.25.8npm:@esbuild/darwin-x640.25.8npm:@esbuild/freebsd-arm640.25.8npm:@esbuild/freebsd-x640.25.8npm:@esbuild/linux-arm0.25.8npm:@esbuild/linux-arm640.25.8npm:@esbuild/linux-ia320.25.8npm:@esbuild/linux-loong640.25.8npm:@esbuild/linux-mips64el0.25.8npm:@esbuild/linux-ppc640.25.8npm:@esbuild/linux-riscv640.25.8npm:@esbuild/linux-s390x0.25.8npm:@esbuild/linux-x640.25.8npm:@esbuild/netbsd-arm640.25.8npm:@esbuild/netbsd-x640.25.8npm:@esbuild/openbsd-arm640.25.8npm:@esbuild/openbsd-x640.25.8npm:@esbuild/openharmony-arm640.25.8npm:@esbuild/sunos-x640.25.8npm:@esbuild/win32-arm640.25.8npm:@esbuild/win32-ia320.25.8npm:@esbuild/win32-x640.25.8npm:@rolldown/pluginutils1.0.0-beta.27npm:@rollup/rollup-android-arm-eabi4.46.1npm:@rollup/rollup-android-arm644.46.1npm:@rollup/rollup-darwin-arm644.46.1npm:@rollup/rollup-darwin-x644.46.1npm:@rollup/rollup-freebsd-arm644.46.1npm:@rollup/rollup-freebsd-x644.46.1npm:@rollup/rollup-linux-arm-gnueabihf4.46.1npm:@rollup/rollup-linux-arm-musleabihf4.46.1npm:@rollup/rollup-linux-arm64-gnu4.46.1npm:@rollup/rollup-linux-arm64-musl4.46.1npm:@rollup/rollup-linux-loongarch64-gnu4.46.1npm:@rollup/rollup-linux-ppc64-gnu4.46.1npm:@rollup/rollup-linux-riscv64-gnu4.46.1npm:@rollup/rollup-linux-riscv64-musl4.46.1npm:@rollup/rollup-linux-s390x-gnu4.46.1npm:@rollup/rollup-linux-x64-gnu4.46.1npm:@rollup/rollup-linux-x64-musl4.46.1npm:@rollup/rollup-win32-arm64-msvc4.46.1npm:@rollup/rollup-win32-ia32-msvc4.46.1npm:@rollup/rollup-win32-x64-msvc4.46.1npm:@swc/core1.13.3npm:@swc/core-darwin-arm641.13.3npm:@swc/core-darwin-x641.13.3npm:@swc/core-linux-arm-gnueabihf1.13.3npm:@swc/core-linux-arm64-gnu1.13.3npm:@swc/core-linux-arm64-musl1.13.3npm:@swc/core-linux-x64-gnu1.13.3npm:@swc/core-linux-x64-musl1.13.3npm:@swc/core-win32-arm64-msvc1.13.3npm:@swc/core-win32-ia32-msvc1.13.3npm:@swc/core-win32-x64-msvc1.13.3npm:@swc/counter0.1.3npm:@swc/types0.1.23npm:@types/command-line-args5.2.0npm:@types/command-line-usage5.0.2npm:@types/estree1.0.8npm:@types/flatbuffers2.0.1npm:@types/node18.7.23 · 22.16.5npm:@types/pad-left2.1.1npm:@types/prop-types15.7.15npm:@types/react18.3.23npm:@types/react-dom18.3.7npm:@vitejs/plugin-react-swc3.11.0pypi:affine2.4.0pypi:aistudio-sdk0.3.8pypi:altair5.5.0 · 6.0.0pypi:annotated-doc0.0.4pypi:annotated-types0.7.0npm:ansi-styles3.2.1npm:apache-arrow11.0.0npm:array-back3.1.0 · 4.0.2pypi:attrs25.3.0 · 26.1.0pypi:bandit1.7.5pypi:bce-python-sdk0.9.68pypi:blinker1.9.0pypi:cachetools6.2.0 · 7.0.5pypi:cfgv3.4.0npm:chalk2.4.2pypi:chardet7.4.0.post2pypi:charset-normalizer3.4.3 · 3.4.6pypi:cligj0.7.2npm:color-convert1.9.3This page displays 120 of 266 ordered rows. The machine-readable dossier retains the complete exact projection.
Certifi removes GLOBALTRUST root certificate
10 Sept 2026GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
08 Sept 2026nanoid: non-secure generators can loop indefinitely with negative size
10 Sept 2026GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
23 Sept 2026nanoid: custom generators can loop indefinitely when size is zero
10 Sept 2026urllib3 streaming API improperly handles highly compressed data
25 Sept 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10 Sept 2026GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
10 Sept 2026UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
10 Sept 2026GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
17 Sept 2026Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
10 Sept 2026GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
23 Sept 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
10 Sept 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10 Sept 2026urllib3 does not control redirects in browsers and Node.js
10 Sept 2026GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
10 Sept 2026Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
10 Sept 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10 Sept 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10 Sept 2026GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
10 Sept 2026virtualenv Has TOCTOU Vulnerabilities in Directory Creation
10 Sept 2026AnyIO process-pool workers can block indefinitely on undrained stderr
18 Sept 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
10 Sept 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
10 Sept 2026Pillow has a heap buffer overflow with nested list coordinates
10 Sept 2026GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
08 Sept 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
10 Sept 2026geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure
10 Jun 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
10 Sept 2026esbuild enables any website to send any requests to the development server and read the response
10 Sept 2026PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
10 Sept 2026GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
10 Sept 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
10 Sept 2026pytest has vulnerable tmpdir handling
10 Sept 2026GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
10 Sept 2026fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
10 Sept 2026GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
23 Sept 2026Tornado has incomplete validation of cookie attributes
10 Sept 2026Tornado vulnerable to excessive logging caused by malformed multipart form data
10 Sept 2026protobuf affected by a JSON recursion depth bypass
10 Sept 2026Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
13 Jul 2026AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
18 Sept 2026tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
16 Sept 2026GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
08 Sept 2026protobuf-python has a potential Denial of Service issue
10 Sept 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
10 Sept 2026vite allows server.fs.deny bypass via backslash on Windows
10 Sept 2026GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
24 Sept 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): SmartPlanAI Anwendung — exact AI dependency evidence dossier, data state 30 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-10162/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools cover related ground.