energieautarkes-wohnquartier/backendThis dossier retains 81 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:6876a231ced00a8d5ac3f1a8fa53fd89e79d737091ef2925e25665b04e92e693pypi:scikit-learn1.6.1pypi:tensorflow2.19.0pypi:pillow11.2.120 OSV records returnedpypi:keras3.9.215 OSV records returnedpypi:urllib32.4.07 OSV records returnedpypi:werkzeug3.1.36 OSV records returnedpypi:flask-cors5.0.15 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:requests2.32.33 OSV records returnedpypi:setuptools80.4.03 OSV records returnedpypi:protobuf5.29.42 OSV records returnedpypi:certifi2025.4.261 OSV record returnedpypi:click8.2.01 OSV record returnedpypi:flask3.1.11 OSV record returnedpypi:fonttools4.58.01 OSV record returnedpypi:idna3.101 OSV record returnedpypi:markdown3.81 OSV record returnedpypi:pygments2.19.11 OSV record returnedpypi:python-dotenv1.1.01 OSV record returnedpypi:wheel0.45.11 OSV record returnedpypi:absl-py2.2.2pypi:astunparse1.6.3pypi:blinker1.9.0pypi:charset-normalizer3.4.2pypi:colorama0.4.6pypi:compress-json1.1.1pypi:contourpy1.3.2pypi:cycler0.12.1pypi:flatbuffers25.2.10pypi:gast0.6.0pypi:google-pasta0.2.0pypi:grpcio1.71.0pypi:gunicorn23.0.0pypi:h5py3.13.0pypi:itsdangerous2.2.0pypi:joblib1.5.0pypi:kiwisolver1.4.8pypi:libclang18.1.1pypi:markdown-it-py3.0.0pypi:markupsafe3.0.2pypi:matplotlib3.10.3pypi:mdurl0.1.2pypi:ml-dtypes0.5.1pypi:namex0.0.9pypi:numpy2.1.3pypi:nvidia-cublas-cu1212.5.3.2pypi:nvidia-cuda-cupti-cu1212.5.82pypi:nvidia-cuda-nvcc-cu1212.5.82pypi:nvidia-cuda-nvrtc-cu1212.5.82pypi:nvidia-cuda-runtime-cu1212.5.82pypi:nvidia-cudnn-cu129.3.0.75pypi:nvidia-cufft-cu1211.2.3.61pypi:nvidia-curand-cu1210.3.6.82pypi:nvidia-cusolver-cu1211.6.3.83pypi:nvidia-cusparse-cu1212.5.1.3pypi:nvidia-nccl-cu122.23.4pypi:nvidia-nvjitlink-cu1212.5.82pypi:opt-einsum3.4.0pypi:optree0.15.0pypi:packaging25.0pypi:pandas2.2.3pypi:plot-keras-history1.1.39pypi:psutil7.0.0pypi:pyparsing3.2.3pypi:python-dateutil2.9.0.post0pypi:python-magic0.4.27pypi:pytz2025.2pypi:rich14.0.0pypi:ruff0.11.10pypi:sanitize-ml-labels1.1.4pypi:scipy1.15.3pypi:six1.17.0pypi:tabulate0.9.0pypi:tensorboard2.19.0pypi:tensorboard-data-server0.7.2pypi:tensorflow-io-gcs-filesystem0.37.1pypi:termcolor3.1.0pypi:threadpoolctl3.6.0pypi:typing-extensions4.13.2pypi:tzdata2025.2pypi:wrapt1.17.2Certifi removes GLOBALTRUST root certificate
10 Jun 2026Keras: HDF5 virtual datasets can disclose local files
10 Aug 2026Werkzeug safe_join() allows Windows special device names
13 Jul 2026Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
07 Jul 2026urllib3 streaming API improperly handles highly compressed data
07 Jul 2026Keras is vulnerable to Deserialization of Untrusted Data
16 Jul 2026The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
06 Jun 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07 Jul 2026Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
13 Jul 2026Flask-CORS vulnerable to Improper Handling of Case Sensitivity
07 Jul 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
22 Jul 2026urllib3 does not control redirects in browsers and Node.js
07 Jul 2026Keras has an untrusted deserialization vulnerability
13 Jul 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
22 Jul 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
13 Jul 2026Keras: tar extraction permits symlink-based path traversal
10 Aug 2026Keras: Lambda deserialization can bypass safe mode and execute code
10 Aug 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
11 May 2026Python-Markdown has an Uncaught Exception
10 Jun 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
22 Jul 2026Pillow has a heap buffer overflow with nested list coordinates
13 Jul 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
23 Jul 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
08 Jul 2026Flask session does not add `Vary: Cookie` header when accessed in some ways
13 Jul 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
22 Jul 2026fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
07 Jul 2026protobuf affected by a JSON recursion depth bypass
07 Jul 2026Flask-CORS improper regex path matching vulnerability
07 Jul 2026flask-cors vulnerable to log injection when the log level is set to debug
10 Jun 2026Werkzeug safe_join() allows Windows special device names with compound extensions
07 Jul 2026protobuf-python has a potential Denial of Service issue
07 Jul 2026Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack
07 Jul 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
22 Jul 2026Flask-CORS allows for inconsistent CORS matching
07 Jul 2026Requests vulnerable to .netrc credentials leak via malicious URLs
07 Jul 2026Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
22 Jul 2026Requests `Session` object does not verify requests after making first request with verify=False
07 Jul 2026Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
29 May 2026Pillow affected by out-of-bounds write when loading PSD images
13 Jul 2026Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
07 Jul 2026setuptools vulnerable to Command Injection via package URL
07 Jul 2026Werkzeug safe_join not safe on Windows
07 Jul 2026Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
23 Jul 2026Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
13 Jul 2026Keras: DiskIOStore permits path traversal through crafted layer names
10 Aug 2026urllib3 allows an unbounded number of links in the decompression chain
07 Jul 2026Jinja has a sandbox breakout through malicious filenames
07 Jul 2026setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
23 Jul 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): Energieautarkes Wohnquartier - Backend — exact AI dependency evidence dossier, data state 12 Aug 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-6174/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools complement the current result.