uba-ki-lab/workshop-green-llm-usageThis dossier retains 78 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:61957e618f66a37d9e215e1c3f28156669993991782385cff9bcc34a70d841cepypi:openai2.7.1pypi:codecarbon3.0.8pypi:tornado6.5.213 OSV records returnedpypi:cryptography46.0.39 OSV records returnedpypi:starlette0.49.38 OSV records returnedpypi:urllib32.5.07 OSV records returnedpypi:requests2.32.53 OSV records returnedpypi:anyio4.11.02 OSV records returnedpypi:certifi2025.10.51 OSV record returnedpypi:click8.3.01 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:idna3.111 OSV record returnedpypi:jupyter-core5.9.11 OSV record returnedpypi:jwcrypto1.5.61 OSV record returnedpypi:pygments2.19.21 OSV record returnedpypi:tqdm4.67.11 OSV record returnedpypi:annotated-doc0.0.3pypi:annotated-types0.7.0pypi:appnope0.1.4pypi:arrow1.4.0pypi:asttokens3.0.0pypi:cffi2.0.0pypi:charset-normalizer3.4.4pypi:colorama0.4.6pypi:comm0.2.3pypi:debugpy1.8.17pypi:decorator5.2.1pypi:distro1.9.0pypi:executing2.2.1pypi:fastapi0.121.1pypi:fief-client0.20.0pypi:httpcore1.0.9pypi:httpx0.27.2pypi:ipykernel7.1.0pypi:ipython9.7.0pypi:ipython-pygments-lexers1.1.1pypi:jedi0.19.2pypi:jiter0.12.0pypi:jupyter-client8.6.3pypi:markdown-it-py4.0.0pypi:matplotlib-inline0.2.1pypi:mdurl0.1.2pypi:nest-asyncio1.6.0pypi:numpy2.3.4pypi:nvidia-ml-py13.580.82pypi:packaging25.0pypi:pandas2.3.3pypi:parso0.8.5pypi:pexpect4.9.0pypi:platformdirs4.5.0pypi:prometheus-client0.23.1pypi:prompt-toolkit3.0.52pypi:psutil7.1.3pypi:ptyprocess0.7.0pypi:pure-eval0.2.3pypi:py-cpuinfo9.0.0pypi:pycparser2.23pypi:pydantic2.12.4pypi:pydantic-core2.41.5pypi:python-dateutil2.9.0.post0pypi:pytz2025.2pypi:pyzmq27.1.0pypi:questionary2.1.1pypi:rapidfuzz3.14.3pypi:rich14.2.0pypi:shellingham1.5.4pypi:six1.17.0pypi:sniffio1.3.1pypi:stack-data0.6.3pypi:termcolor3.2.0pypi:traitlets5.14.3pypi:typer0.20.0pypi:typing-extensions4.15.0pypi:typing-inspection0.4.2pypi:tzdata2025.2pypi:uvicorn0.38.0pypi:wcwidth0.2.14pypi:yaspin3.3.0Certifi removes GLOBALTRUST root certificate
10 Sept 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
10 Sept 2026urllib3 streaming API improperly handles highly compressed data
25 Sept 2026Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
10 Sept 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10 Sept 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
10 Sept 2026urllib3 does not control redirects in browsers and Node.js
10 Sept 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10 Sept 2026Vulnerable OpenSSL included in cryptography wheels
10 Sept 2026AnyIO process-pool workers can block indefinitely on undrained stderr
18 Sept 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
10 Sept 2026Tornado has incomplete validation of cookie attributes
10 Sept 2026Vulnerable OpenSSL included in cryptography wheels
10 Sept 2026Tornado vulnerable to excessive logging caused by malformed multipart form data
10 Sept 2026Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
10 Sept 2026AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
18 Sept 2026Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
10 Sept 2026tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
16 Sept 2026Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
10 Sept 2026Requests vulnerable to .netrc credentials leak via malicious URLs
10 Sept 2026Requests `Session` object does not verify requests after making first request with verify=False
10 Sept 2026Tornado: Quadratic DoS via Repeated Header Coalescing
20 Jul 2026Tornado has out-of-bounds memory access via C extension
10 Sept 2026Starlette Denial of service (DoS) via multipart/form-data
10 Sept 2026JWCrypto: JWE ZIP decompression bomb
10 Sept 2026cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
10 Sept 2026tqdm CLI arguments injection attack
10 Sept 2026Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
10 Sept 2026urllib3 allows an unbounded number of links in the decompression chain
10 Sept 2026pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
10 Sept 2026Tornado: Quadratic DoS via Crafted Multipart Parameters
20 Jul 2026Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
10 Sept 2026python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
24 Sept 2026python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
24 Sept 2026cryptography has incomplete DNS name constraint enforcement on peer names
10 Sept 2026urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
10 Sept 2026tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
10 Sept 2026Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
10 Sept 2026Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
10 Sept 2026urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
10 Sept 2026Tornado vulnerable to Header Injection and XSS via reason argument
20 Jul 2026Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
16 Sept 2026urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
10 Sept 2026Tornado is vulnerable to DoS due to too many multipart parts
10 Sept 2026cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
10 Sept 2026h11 accepts some malformed Chunked-Encoding bodies
10 Sept 2026Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
10 Sept 2026Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
16 Sept 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): Workshop Green LLM Usage — exact AI dependency evidence dossier, data state 30 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-7788/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools cover related ground.