uba-ki-lab/retrieval-evaluationThis dossier retains 150 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:2b93eec49931aff00a2c694c2c913da38d615033ab4eb9432fdb647839db6dc5pypi:transformers4.57.125 OSV records returnedpypi:torch2.9.123 OSV records returnedpypi:anthropic0.46.0pypi:datasets4.4.1pypi:llama-index-embeddings-openai-like0.2.2pypi:openai1.109.1pypi:tokenizers0.22.1pypi:llama-index-core0.14.8pypi:llama-index-vector-stores-milvus0.9.3pypi:pymilvus2.6.3pypi:scikit-learn1.7.2pypi:tiktoken0.12.0pypi:aiohttp3.13.233 OSV records returnedpypi:pillow10.4.020 OSV records returnedpypi:nltk3.9.216 OSV records returnedpypi:urllib32.5.07 OSV records returnedpypi:pyasn10.6.15 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:requests2.32.53 OSV records returnedpypi:setuptools80.9.03 OSV records returnedpypi:filelock3.20.02 OSV records returnedpypi:protobuf6.33.12 OSV records returnedpypi:soupsieve2.82 OSV records returnedpypi:banks2.2.01 OSV record returnedpypi:certifi2025.11.121 OSV record returnedpypi:click8.3.11 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:idna3.111 OSV record returnedpypi:lxml6.0.21 OSV record returnedpypi:markdown3.101 OSV record returnedpypi:marshmallow3.26.11 OSV record returnedpypi:orjson3.11.41 OSV record returnedpypi:pyarrow22.0.01 OSV record returnedpypi:pydantic-settings2.12.01 OSV record returnedpypi:pygments2.19.21 OSV record returnedpypi:python-dotenv1.2.11 OSV record returnedpypi:tqdm4.67.11 OSV record returnedpypi:virtualenv20.35.41 OSV record returnedpypi:aiohappyeyeballs2.6.1pypi:aiosignal1.4.0pypi:aiosqlite0.21.0pypi:annotated-types0.7.0pypi:antlr4-python3-runtime4.9.3pypi:anyio4.11.0pypi:argilla2.8.0pypi:attrs25.4.0pypi:beautifulsoup44.14.2pypi:cachetools6.2.2pypi:cfgv3.4.0pypi:charset-normalizer3.4.4pypi:colorama0.4.6pypi:dataclasses-json0.6.7pypi:deprecated1.3.1pypi:dill0.4.0pypi:dirtyjson1.0.8pypi:distlib0.4.0pypi:distro1.9.0pypi:einops0.8.1pypi:filetype1.2.0pypi:frozenlist1.8.0pypi:fsspec2025.10.0pypi:ftfy6.3.1pypi:google-auth2.43.0pypi:google-genai1.50.1pypi:greenlet3.2.4pypi:griffe1.15.0pypi:grpcio1.76.0pypi:hf-xet1.2.0pypi:httpcore1.0.9pypi:httpx0.28.1pypi:huggingface-hub0.36.0pypi:hydra-core1.3.2pypi:identify2.6.15pypi:jiter0.12.0pypi:joblib1.5.2pypi:llama-index-embeddings-openai0.5.1pypi:llama-index-instrumentation0.4.2pypi:llama-index-workflows2.11.1pypi:markdown-it-py4.0.0pypi:markdown22.5.4pypi:markdownify1.2.2pypi:marker-pdf1.10.1pypi:markupsafe3.0.3pypi:mdurl0.1.2pypi:milvus-lite2.5.1pypi:mpmath1.3.0pypi:multidict6.7.0pypi:multiprocess0.70.18pypi:mypy-extensions1.1.0pypi:nest-asyncio1.6.0pypi:networkx3.5pypi:nodeenv1.9.1pypi:numpy2.3.5pypi:nvidia-cublas-cu1212.8.4.1pypi:nvidia-cuda-cupti-cu1212.8.90pypi:nvidia-cuda-nvrtc-cu1212.8.93pypi:nvidia-cuda-runtime-cu1212.8.90pypi:nvidia-cudnn-cu129.10.2.21pypi:nvidia-cufft-cu1211.3.3.83pypi:nvidia-cufile-cu121.13.1.3pypi:nvidia-curand-cu1210.3.9.90pypi:nvidia-cusolver-cu1211.7.3.90pypi:nvidia-cusparse-cu1212.5.8.93pypi:nvidia-cusparselt-cu120.7.1pypi:nvidia-nccl-cu122.27.5pypi:nvidia-nvjitlink-cu1212.8.93pypi:nvidia-nvshmem-cu123.3.20pypi:nvidia-nvtx-cu1212.8.90pypi:omegaconf2.3.0pypi:opencv-python-headless4.11.0.86pypi:packaging25.0pypi:pandas2.3.3pypi:pdftext0.6.3pypi:pikepdf10.0.2pypi:platformdirs4.5.0pypi:pre-commit4.4.0pypi:propcache0.4.1pypi:pyasn1-modules0.4.2pypi:pydantic2.12.4pypi:pydantic-core2.41.5This page displays 120 of 150 ordered rows. The machine-readable dossier retains the complete exact projection.
Certifi removes GLOBALTRUST root certificate
10 Jun 2026HuggingFace transformers vulnerable to remote code execution
13 Jul 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
13 Jul 2026AIOHTTP has CRLF injection through multipart part content type header construction
13 Jul 2026Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
13 Jul 2026urllib3 streaming API improperly handles highly compressed data
07 Jul 2026PyTorch susceptible to local Denial of Service
10 Jun 2026Transformers is vulnerable to ReDoS attack through its DonutProcessor class
07 Jul 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07 Jul 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
13 Jul 2026Marshmallow has DoS in Schema.load(many)
07 Jul 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
22 Jul 2026NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
13 Jul 2026urllib3 does not control redirects in browsers and Node.js
07 Jul 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
13 Jul 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
27 Jun 2026Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
07 Jul 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
22 Jul 2026pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
08 Jul 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
13 Jul 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07 Aug 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
07 Jul 2026virtualenv Has TOCTOU Vulnerabilities in Directory Creation
07 Jul 2026Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
07 Jul 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
11 May 2026Python-Markdown has an Uncaught Exception
10 Jun 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
22 Jul 2026Pillow has a heap buffer overflow with nested list coordinates
13 Jul 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
23 Jul 2026AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
16 Jul 2026aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
13 Jul 2026pyasn1 has a DoS vulnerability in decoder
21 Jul 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
08 Jul 2026NLTK has a Path Traversal issue
10 Jun 2026AIOHTTP's unicode processing of header values could cause parsing discrepancies
07 Jul 2026HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
13 Jul 2026Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
06 Aug 2026AIOHTTP vulnerable to denial of service through large payloads
07 Jul 2026AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
07 Jul 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
22 Jul 2026Transformers Regular Expression Denial of Service (ReDoS) vulnerability
07 Jul 2026protobuf affected by a JSON recursion depth bypass
07 Jul 2026NLTK has a Zip Slip Vulnerability
10 Jun 2026Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
13 Jul 2026PyTorch Improper Resource Shutdown or Release vulnerability
07 Aug 2026pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
23 Jul 2026protobuf-python has a potential Denial of Service issue
07 Jul 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
22 Jul 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): Retrieval Evaluation — exact AI dependency evidence dossier, data state 12 Aug 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-7811/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools complement the current result.