← Back to the AI Dependency AtlasExact repository supply-chain dossier

Datastore

f13/microservices/datastore
pypi

This dossier retains 119 exact component occurrences from 3 published evidence files at one immutable repository commit.

opencode:9852d69c3e5b02c3project ID + commit SHA + exact evidence path

Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.

project ID + commit SHA + exact evidence path
119exact component occurrences
117package identities
3evidence files
118OSV records returned
Exact published evidence

Files that resolve this repository’s dependencies

Every file remains tied to the observed commit. A parse error stays visible and never becomes a zero.

Evidence pathrequirements-dev.txt
Format
exact-manifest-pin
Parser state
parsed
Resolved components
1
Open exact source ↗
Evidence pathrequirements.txt
Format
exact-manifest-pin
Parser state
parsed
Resolved components
1
Open exact source ↗
Evidence pathuv.locksha256:6595b6f54571e9af6cc1d55f3a760e5ca4e6191eb5043f8cea081d53d833f9e6
Format
uv-lock
Parser state
parsed
Resolved components
117
Open exact source ↗
Observed relations

Package identities at this commit

pypiOpenAI SDKpypi:openai
3 Occurrences2.45.0
Apache-2.0
→
pypiaiohttppypi:aiohttp
1 Occurrence3.14.3
Apache-2.0 · Apache-2.0 AND MIT33 OSV records returned
→
pypipyjwtpypi:pyjwt
1 Occurrence2.15.1
MIT20 OSV records returned
pypiurllib3pypi:urllib3
1 Occurrence2.7.0
MIT10 OSV records returned
→
pypicryptographypypi:cryptography
1 Occurrence50.0.0
Apache-2.0 OR BSD-3-Clause9 OSV records returned
→
pypipython-multipartpypi:python-multipart
1 Occurrence0.0.32
Apache-2.08 OSV records returned
pypistarlettepypi:starlette
1 Occurrence1.3.1
BSD-3-Clause8 OSV records returned
→
pypivirtualenvpypi:virtualenv
1 Occurrence21.7.1
MIT5 OSV records returned
pypijinja2pypi:jinja2
1 Occurrence3.1.6
BSD-3-Clause · non-standard4 OSV records returned
→
pypimcppypi:mcp
1 Occurrence1.29.0
MIT3 OSV records returned
pypirequestspypi:requests
1 Occurrence2.34.2
Apache-2.03 OSV records returned
→
pypianyiopypi:anyio
1 Occurrence4.14.2
MIT2 OSV records returned
→
pypifilelockpypi:filelock
1 Occurrence3.32.2
MIT · Unlicense2 OSV records returned
→
pypiprotobufpypi:protobuf
1 Occurrence7.35.1
BSD-3-Clause2 OSV records returned
→
pypicertifipypi:certifi
1 Occurrence2026.6.17
MPL-2.01 OSV record returned
→
pypiclickpypi:click
1 Occurrence8.4.2
BSD-3-Clause · non-standard1 OSV record returned
→
pypih11pypi:h11
1 Occurrence0.16.0
MIT1 OSV record returned
→
pypiidnapypi:idna
1 Occurrence3.18
BSD-3-Clause · non-standard1 OSV record returned
→
pypipydantic-settingspypi:pydantic-settings
1 Occurrence2.14.2
MIT1 OSV record returned
pypipygmentspypi:pygments
1 Occurrence2.20.0
BSD-2-Clause1 OSV record returned
→
pypipytestpypi:pytest
1 Occurrence9.1.1
MIT1 OSV record returned
pypipython-dotenvpypi:python-dotenv
1 Occurrence1.2.2
BSD-3-Clause1 OSV record returned
→
pypitqdmpypi:tqdm
1 Occurrence4.68.4
MIT AND MPL-2.01 OSV record returned
→
pypiaiohappyeyeballspypi:aiohappyeyeballs
1 Occurrence2.7.1
PSF-2.0
pypiaiosignalpypi:aiosignal
1 Occurrence1.4.0
Apache-2.0
pypiamqppypi:amqp
1 Occurrence5.3.1
non-standard
pypiannotated-docpypi:annotated-doc
1 Occurrence0.0.4
MIT
pypiannotated-typespypi:annotated-types
1 Occurrence0.7.0
MIT
pypiast-serializepypi:ast-serialize
1 Occurrence0.6.0
MIT
pypiattrspypi:attrs
1 Occurrence26.1.0
MIT
pypibilliardpypi:billiard
1 Occurrence4.2.4
non-standard
pypiboolean-pypypi:boolean-py
1 Occurrence5.0
BSD-2-Clause
pypiboto3pypi:boto3
1 Occurrence1.43.46
Apache-2.0
pypibotocorepypi:botocore
1 Occurrence1.43.46
Apache-2.0
pypicelerypypi:celery
1 Occurrence5.6.3
BSD-3-Clause
pypicelery-typespypi:celery-types
1 Occurrence0.26.0
Apache-2.0
pypicffipypi:cffi
1 Occurrence2.1.0
MIT · MIT-0
pypicfgvpypi:cfgv
1 Occurrence3.5.0
MIT
pypicharset-normalizerpypi:charset-normalizer
1 Occurrence3.4.9
MIT
pypiclick-didyoumeanpypi:click-didyoumean
1 Occurrence0.3.1
MIT
pypiclick-pluginspypi:click-plugins
1 Occurrence1.1.1.2
non-standard
pypiclick-replpypi:click-repl
1 Occurrence0.3.0
MIT
pypicoloramapypi:colorama
1 Occurrence0.4.6
non-standard
pypicoveragepypi:coverage
1 Occurrence7.15.1
Apache-2.0
pypidistlibpypi:distlib
1 Occurrence0.4.3
PSF-2.0
pypidistropypi:distro
1 Occurrence1.9.0
Apache-2.0
pypieventspypi:events
1 Occurrence0.5
non-standard
pypifastapipypi:fastapi
1 Occurrence0.139.0
MIT
pypifastapi-mcppypi:fastapi-mcp
1 Occurrence0.4.0
non-standard
pypifrozenlistpypi:frozenlist
1 Occurrence1.8.0
Apache-2.0
pypigrpciopypi:grpcio
1 Occurrence1.82.1
Apache-2.0
pypihttpcorepypi:httpcore
1 Occurrence1.0.9
BSD-3-Clause
pypihttptoolspypi:httptools
1 Occurrence0.8.0
MIT
pypihttpxpypi:httpx
1 Occurrence0.28.1
BSD-3-Clause
pypihttpx-ssepypi:httpx-sse
1 Occurrence0.4.3
MIT
pypiidentifypypi:identify
1 Occurrence2.6.19
MIT
pypiiniconfigpypi:iniconfig
1 Occurrence2.3.0
MIT
pypijiterpypi:jiter
1 Occurrence0.16.0
MIT
pypijmespathpypi:jmespath
1 Occurrence1.1.0
MIT
pypijsonschemapypi:jsonschema
1 Occurrence4.26.0
MIT
pypijsonschema-specificationspypi:jsonschema-specifications
1 Occurrence2025.9.1
MIT
pypikombupypi:kombu
1 Occurrence5.6.2
BSD-3-Clause
pypilibrtpypi:librt
1 Occurrence0.13.0
MIT
pypilicense-expressionpypi:license-expression
1 Occurrence30.4.4
Apache-2.0
pypimarkdown-it-pypypi:markdown-it-py
1 Occurrence4.2.0
MIT
pypimarkupsafepypi:markupsafe
1 Occurrence3.0.3
BSD-3-Clause · non-standard
pypimdurlpypi:mdurl
1 Occurrence0.1.2
MIT
pypimultidictpypi:multidict
1 Occurrence6.7.1
Apache-2.0
pypimypypypi:mypy
1 Occurrence2.3.0
MIT
pypimypy-extensionspypi:mypy-extensions
1 Occurrence1.1.0
MIT
pypinodeenvpypi:nodeenv
1 Occurrence1.10.0
non-standard
pypiopensearch-protobufspypi:opensearch-protobufs
1 Occurrence1.2.0
Apache-2.0
pypiopensearch-pypypi:opensearch-py
1 Occurrence3.2.0
Apache-2.0
pypipackagingpypi:packaging
1 Occurrence26.2
Apache-2.0 OR BSD-2-Clause · non-standard
pypipathspecpypi:pathspec
1 Occurrence1.1.1
MPL-2.0
pypiplatformdirspypi:platformdirs
1 Occurrence4.11.0
MIT
pypipluggypypi:pluggy
1 Occurrence1.6.0
MIT
pypipre-commitpypi:pre-commit
1 Occurrence4.5.1
MIT
pypiprompt-toolkitpypi:prompt-toolkit
1 Occurrence3.0.52
BSD-3-Clause · non-standard
pypipropcachepypi:propcache
1 Occurrence0.5.2
Apache-2.0
pypipycparserpypi:pycparser
1 Occurrence3.0
BSD-3-Clause
pypipydanticpypi:pydantic
1 Occurrence2.13.4
MIT
pypipydantic-corepypi:pydantic-core
1 Occurrence2.46.4
MIT
pypipytest-asynciopypi:pytest-asyncio
1 Occurrence1.4.0
Apache-2.0
pypipytest-covpypi:pytest-cov
1 Occurrence7.1.0
MIT
pypipython-dateutilpypi:python-dateutil
1 Occurrence2.9.0.post0
non-standard
pypipython-debianpypi:python-debian
1 Occurrence1.1.1
GPL-2.0-or-later
pypipython-discoverypypi:python-discovery
1 Occurrence1.5.0
non-standard
pypipython-magicpypi:python-magic
1 Occurrence0.4.27
MIT
pypipywin32pypi:pywin32
1 Occurrence312
Not reported
pypipyyamlpypi:pyyaml
1 Occurrence6.0.3
MIT
pypireferencingpypi:referencing
1 Occurrence0.37.0
MIT
pypirespxpypi:respx
1 Occurrence0.23.1
BSD-3-Clause
pypireusepypi:reuse
1 Occurrence6.2.0
Apache-2.0 AND CC-BY-SA-4.0 AND CC0-1.0 AND GPL-3.0-or-later
pypirichpypi:rich
1 Occurrence15.0.0
MIT
pypirpds-pypypi:rpds-py
1 Occurrence2026.6.3
MIT
pypiruffpypi:ruff
1 Occurrence0.15.21
MIT
pypis3transferpypi:s3transfer
1 Occurrence0.19.1
Apache-2.0
pypishellinghampypi:shellingham
1 Occurrence1.5.4
non-standard
pypisixpypi:six
1 Occurrence1.17.0
MIT
pypisniffiopypi:sniffio
1 Occurrence1.3.1
Apache-2.0 OR MIT
pypisse-starlettepypi:sse-starlette
1 Occurrence3.4.5
BSD-3-Clause
pypitenacitypypi:tenacity
1 Occurrence9.1.4
Apache-2.0
pypitomlipypi:tomli
1 Occurrence2.4.1
MIT
pypitomlkitpypi:tomlkit
1 Occurrence0.15.0
MIT
pypityperpypi:typer
1 Occurrence0.26.8
MIT
pypityping-extensionspypi:typing-extensions
1 Occurrence4.16.0
PSF-2.0 · non-standard
pypityping-inspectionpypi:typing-inspection
1 Occurrence0.4.2
MIT
pypitzdatapypi:tzdata
1 Occurrence2026.3
Apache-2.0
pypitzlocalpypi:tzlocal
1 Occurrence5.4.4
MIT
pypiuvicornpypi:uvicorn
1 Occurrence0.51.0
BSD-3-Clause
pypiuvlooppypi:uvloop
1 Occurrence0.22.1
MIT
pypivinepypi:vine
1 Occurrence5.1.0
non-standard
pypiwatchfilespypi:watchfiles
1 Occurrence1.2.0
MIT
pypiwcwidthpypi:wcwidth
1 Occurrence0.8.2
MIT
pypiwebsocketspypi:websockets
1 Occurrence16.1
BSD-3-Clause
pypiyarlpypi:yarl
1 Occurrence1.24.2
Apache-2.0
OSV

Related OSV records

GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

1 repository10 Sept 2026
GHSA-2c2j-9gv5-cj73

Starlette has possible denial-of-service vector when parsing large files in multipart forms

4 repositories10 Sept 2026
GHSA-2fqr-mr3j-6wp8

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

11 repositories10 Sept 2026
GHSA-2gx3-rcp4-g85q

PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)

5 repositories30 Sept 2026
GHSA-2vrm-gr82-f7m5

AIOHTTP has CRLF injection through multipart part content type header construction

10 repositories10 Sept 2026
GHSA-2xpw-w6gg-jr37

urllib3 streaming API improperly handles highly compressed data

16 repositories25 Sept 2026
→
GHSA-38jv-5279-wg99

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

16 repositories10 Sept 2026
GHSA-3wq7-rqq7-wx6j

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

10 repositories10 Sept 2026
GHSA-42vr-xj54-vc7v

PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)

5 repositories30 Sept 2026
GHSA-48p4-8xcf-vxj5

urllib3 does not control redirects in browsers and Node.js

8 repositories10 Sept 2026
GHSA-4fvr-rgm6-gqmc

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

11 repositories10 Sept 2026
GHSA-4m7w-qmgq-4wj5

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

11 repositories10 Sept 2026
GHSA-4xgf-cpjx-pc3j

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

2 repositories10 Sept 2026
GHSA-5239-wwwm-4pmq

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

15 repositories10 Sept 2026
GHSA-537c-gmf6-5ccf

Vulnerable OpenSSL included in cryptography wheels

7 repositories10 Sept 2026
GHSA-54jq-c3m8-4m76

AIOHTTP vulnerable to brute-force leak of internal static file path components

8 repositories10 Sept 2026
GHSA-597g-3phw-6986

virtualenv Has TOCTOU Vulnerabilities in Directory Creation

7 repositories10 Sept 2026
GHSA-59g5-xgcq-4qw3

Denial of service (DoS) via deformation `multipart/form-data` boundary

1 repository10 Sept 2026
GHSA-5p39-cfhj-2xmp

AnyIO process-pool workers can block indefinitely on undrained stderr

16 repositories18 Sept 2026
GHSA-5rvq-cxj2-64vf

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

7 repositories10 Sept 2026
GHSA-63hf-3vf5-4wqf

AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass

10 repositories10 Sept 2026
GHSA-63hw-fmq6-xxg2

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

11 repositories10 Sept 2026
GHSA-65pc-fj4g-8rjx

Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix

21 repositories10 Sept 2026
→
GHSA-69f9-5gxw-wvc2

AIOHTTP's unicode processing of header values could cause parsing discrepancies

8 repositories10 Sept 2026
GHSA-6jhg-hg63-jvvf

AIOHTTP vulnerable to denial of service through large payloads

8 repositories10 Sept 2026
GHSA-6jv3-5f52-599m

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

7 repositories10 Sept 2026
GHSA-6mq8-rvhq-8wgg

AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb

8 repositories10 Sept 2026
GHSA-6w46-j5rx-g56g

pytest has vulnerable tmpdir handling

7 repositories10 Sept 2026
GHSA-752w-5fwx-jx9f

PyJWT accepts unknown `crit` header extensions

3 repositories10 Sept 2026
GHSA-79v4-65xg-pq4g

Vulnerable OpenSSL included in cryptography wheels

3 repositories10 Sept 2026
GHSA-7f5h-v6xp-fcq8

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

6 repositories10 Sept 2026
GHSA-7gcm-g887-7qv7

protobuf affected by a JSON recursion depth bypass

13 repositories10 Sept 2026
GHSA-82r6-8w77-94w6

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

16 repositories18 Sept 2026
GHSA-82w8-qh3p-5jfq

Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS

10 repositories10 Sept 2026
GHSA-86qp-5c8j-p5mr

Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

10 repositories10 Sept 2026
GHSA-8988-9cw3-xx77

urllib3: HTTPS proxy TLS configuration may be ignored or overridden

22 repositories30 Sept 2026
→
GHSA-8qvm-5x2c-j2w7

protobuf-python has a potential Denial of Service issue

3 repositories10 Sept 2026
GHSA-8wjv-2p76-3863

PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header

2 repositories30 Sept 2026
GHSA-94p9-xgh2-xp45

virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use

9 repositories01 Oct 2026
GHSA-9548-qrrj-x5pj

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

4 repositories10 Sept 2026
GHSA-966j-vmvw-g2g9

AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect

10 repositories10 Sept 2026
GHSA-993g-76c3-p5m4

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

3 repositories10 Sept 2026
GHSA-9h52-p55h-vw2f

Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default

3 repositories10 Sept 2026
GHSA-9h9j-4vrj-gf7g

virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

9 repositories01 Oct 2026
GHSA-9hjg-9r4m-mvj7

Requests vulnerable to .netrc credentials leak via malicious URLs

8 repositories10 Sept 2026
GHSA-9j54-fg26-wv3r

PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation

2 repositories30 Sept 2026
GHSA-9v7f-9g4p-ffgj

PyJWT: PyJWKClient follows redirects when fetching JWKS

5 repositories30 Sept 2026
GHSA-9wx4-h78v-vm56

Requests `Session` object does not verify requests after making first request with verify=False

1 repository10 Sept 2026
Interpretation boundary

Exact identities in, explicit limits out

The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.

Retrieval, parsing, matching and publishing use no generative AI model.

i6eal (2026): Datastore — exact AI dependency evidence dossier, data state 01 Oct 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-9852/

Reading this dossier

Does this repository dossier prove deployment?
No. It documents dependencies published at one observed commit, not a deployed environment.
Why are exact versions required?
OSV and registry metadata can be linked reproducibly only to an observed package@version tuple. The collector never substitutes a newest release for a range.
Does a missing row mean the dependency is absent?
No. It means not observed within the bounded files and repository checkpoint. Incomplete trees and parser failures remain explicit.

Need a permanent dependency evidence trail for another public code cohort?

We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.

Discuss a data projectExplore all tools