← Zurück zum KI-AbhängigkeitsatlasExaktes Repository-Lieferkettendossier

SmartPlanAI Anwendung

sh/digitalhub-sh/landesprogramm-offene-innovationen/ki-bauleitplaene/smartplanai-anwendung
npm · pypi

Dieses Dossier bewahrt 318 exakte Komponentenvorkommen aus 3 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.

opencode:101621d70807d48a8Projekt-ID + Commit-SHA + exakter Evidenzpfad

Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.

Projekt-ID + Commit-SHA + exakter Evidenzpfad
318exakte Komponentenvorkommen
266Paketidentitäten
3Evidenzdateien
108zurückgegebene OSV-Meldungen
Exakte veröffentlichte Evidenz

Dateien, die Abhängigkeiten dieses Repositories auflösen

Jede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.

Evidenzpfadblp_streamlit_pipeline/src/ext/streamlit-draw-image-mask/draw_image_mask/draw_image_mask/frontend/package-lock.jsonsha256:d6cf494bd944eff796a59b32b36c8214816e3be6639d5c2ea67893310aa39322
Format
npm-lock
Parserstatus
parsed
Aufgelöste Komponenten
123
Exakte Quelle öffnen ↗
Evidenzpfadblp_streamlit_pipeline/src/ext/streamlit-draw-image-mask/poetry.locksha256:834ae2be07a53839d9a28b3e1f69e45e947515a00364ef07871b6fc47c379933
Format
poetry-lock
Parserstatus
parsed
Aufgelöste Komponenten
78
Exakte Quelle öffnen ↗
Evidenzpfadpoetry.locksha256:aeab690097e8e006cb4680cb53d452b805b943ab2091762607ff4d493cc71549
Format
poetry-lock
Parserstatus
parsed
Aufgelöste Komponenten
117
Exakte Quelle öffnen ↗
Beobachtete Beziehungen

Paketidentitäten an diesem Commit

pypiOpenCVpypi:opencv-python
2 Vorkommen4.12.0.88 · 4.13.0.92
Apache-2.0
pypigitpythonpypi:gitpython
2 Vorkommen3.1.45 · 3.1.46
BSD-3-Clause22 zurückgegebene OSV-Meldungen
pypipillowpypi:pillow
2 Vorkommen11.3.0 · 12.1.1
HPND · MIT-CMU20 zurückgegebene OSV-Meldungen
pypitornadopypi:tornado
2 Vorkommen6.5.2 · 6.5.5
Apache-2.010 zurückgegebene OSV-Meldungen
pypiurllib3pypi:urllib3
2 Vorkommen2.5.0 · 2.6.3
MIT7 zurückgegebene OSV-Meldungen
npmvitenpm:vite
1 Vorkommen6.3.5
MIT7 zurückgegebene OSV-Meldungen
pypijinja2pypi:jinja2
2 Vorkommen3.1.6
BSD-3-Clause · non-standard4 zurückgegebene OSV-Meldungen
npmpostcssnpm:postcss
1 Vorkommen8.5.6
MIT4 zurückgegebene OSV-Meldungen
pypiujsonpypi:ujson
1 Vorkommen5.12.0
BSD-3-Clause · BSD-3-Clause AND TCL · TCL4 zurückgegebene OSV-Meldungen
pypirequestspypi:requests
2 Vorkommen2.32.5 · 2.33.1
Apache-2.03 zurückgegebene OSV-Meldungen
pypisetuptoolspypi:setuptools
2 Vorkommen80.9.0 · 82.0.1
MIT3 zurückgegebene OSV-Meldungen
pypifilelockpypi:filelock
2 Vorkommen3.19.1 · 3.25.2
MIT · Unlicense2 zurückgegebene OSV-Meldungen
npmnanoidnpm:nanoid
1 Vorkommen3.3.11
MIT2 zurückgegebene OSV-Meldungen
npmpicomatchnpm:picomatch
1 Vorkommen4.0.3
MIT2 zurückgegebene OSV-Meldungen
pypiprotobufpypi:protobuf
2 Vorkommen6.32.0 · 6.33.6
BSD-3-Clause2 zurückgegebene OSV-Meldungen
pypistreamlitpypi:streamlit
2 Vorkommen1.49.0 · 1.55.0
Apache-2.02 zurückgegebene OSV-Meldungen
pypicertifipypi:certifi
2 Vorkommen2025.8.3 · 2026.2.25
MPL-2.01 zurückgegebene OSV-Meldung
pypiclickpypi:click
2 Vorkommen8.1.8 · 8.3.1
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
npmesbuildnpm:esbuild
1 Vorkommen0.25.8
MIT1 zurückgegebene OSV-Meldung
pypifonttoolspypi:fonttools
1 Vorkommen4.62.1
MIT1 zurückgegebene OSV-Meldung
pypigeopandaspypi:geopandas
1 Vorkommen1.1.3
BSD-3-Clause1 zurückgegebene OSV-Meldung
pypih11pypi:h11
1 Vorkommen0.16.0
MIT1 zurückgegebene OSV-Meldung
pypiidnapypi:idna
2 Vorkommen3.10 · 3.11
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
pypipyarrowpypi:pyarrow
2 Vorkommen21.0.0 · 23.0.1
Apache-2.0 · non-standard1 zurückgegebene OSV-Meldung
pypipycryptodomepypi:pycryptodome
1 Vorkommen3.23.0
non-standard1 zurückgegebene OSV-Meldung
pypipygmentspypi:pygments
2 Vorkommen2.19.2 · 2.20.0
BSD-2-Clause1 zurückgegebene OSV-Meldung
pypipytestpypi:pytest
1 Vorkommen8.3.2
MIT1 zurückgegebene OSV-Meldung
npmrollupnpm:rollup
1 Vorkommen4.46.1
MIT1 zurückgegebene OSV-Meldung
pypitqdmpypi:tqdm
1 Vorkommen4.67.3
MIT AND MPL-2.01 zurückgegebene OSV-Meldung
pypivirtualenvpypi:virtualenv
1 Vorkommen20.34.0
MIT1 zurückgegebene OSV-Meldung
npm@esbuild/aix-ppc64npm:@esbuild/aix-ppc64
1 Vorkommen0.25.8
MIT
npm@esbuild/android-armnpm:@esbuild/android-arm
1 Vorkommen0.25.8
MIT
npm@esbuild/android-arm64npm:@esbuild/android-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/android-x64npm:@esbuild/android-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/darwin-arm64npm:@esbuild/darwin-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/darwin-x64npm:@esbuild/darwin-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/freebsd-arm64npm:@esbuild/freebsd-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/freebsd-x64npm:@esbuild/freebsd-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-armnpm:@esbuild/linux-arm
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-arm64npm:@esbuild/linux-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-ia32npm:@esbuild/linux-ia32
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-loong64npm:@esbuild/linux-loong64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-mips64elnpm:@esbuild/linux-mips64el
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-ppc64npm:@esbuild/linux-ppc64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-riscv64npm:@esbuild/linux-riscv64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-s390xnpm:@esbuild/linux-s390x
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-x64npm:@esbuild/linux-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/netbsd-arm64npm:@esbuild/netbsd-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/netbsd-x64npm:@esbuild/netbsd-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/openbsd-arm64npm:@esbuild/openbsd-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/openbsd-x64npm:@esbuild/openbsd-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/openharmony-arm64npm:@esbuild/openharmony-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/sunos-x64npm:@esbuild/sunos-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/win32-arm64npm:@esbuild/win32-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/win32-ia32npm:@esbuild/win32-ia32
1 Vorkommen0.25.8
MIT
npm@esbuild/win32-x64npm:@esbuild/win32-x64
1 Vorkommen0.25.8
MIT
npm@rolldown/pluginutilsnpm:@rolldown/pluginutils
1 Vorkommen1.0.0-beta.27
MIT
npm@rollup/rollup-android-arm-eabinpm:@rollup/rollup-android-arm-eabi
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-android-arm64npm:@rollup/rollup-android-arm64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-darwin-arm64npm:@rollup/rollup-darwin-arm64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-darwin-x64npm:@rollup/rollup-darwin-x64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-freebsd-arm64npm:@rollup/rollup-freebsd-arm64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-freebsd-x64npm:@rollup/rollup-freebsd-x64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-arm-gnueabihfnpm:@rollup/rollup-linux-arm-gnueabihf
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-arm-musleabihfnpm:@rollup/rollup-linux-arm-musleabihf
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-arm64-gnunpm:@rollup/rollup-linux-arm64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-arm64-muslnpm:@rollup/rollup-linux-arm64-musl
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-loongarch64-gnunpm:@rollup/rollup-linux-loongarch64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-ppc64-gnunpm:@rollup/rollup-linux-ppc64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-riscv64-gnunpm:@rollup/rollup-linux-riscv64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-riscv64-muslnpm:@rollup/rollup-linux-riscv64-musl
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-s390x-gnunpm:@rollup/rollup-linux-s390x-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-x64-gnunpm:@rollup/rollup-linux-x64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-x64-muslnpm:@rollup/rollup-linux-x64-musl
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-win32-arm64-msvcnpm:@rollup/rollup-win32-arm64-msvc
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-win32-ia32-msvcnpm:@rollup/rollup-win32-ia32-msvc
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-win32-x64-msvcnpm:@rollup/rollup-win32-x64-msvc
1 Vorkommen4.46.1
MIT
npm@swc/corenpm:@swc/core
1 Vorkommen1.13.3
Apache-2.0
npm@swc/core-darwin-arm64npm:@swc/core-darwin-arm64
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-darwin-x64npm:@swc/core-darwin-x64
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-linux-arm-gnueabihfnpm:@swc/core-linux-arm-gnueabihf
1 Vorkommen1.13.3
Apache-2.0
npm@swc/core-linux-arm64-gnunpm:@swc/core-linux-arm64-gnu
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-linux-arm64-muslnpm:@swc/core-linux-arm64-musl
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-linux-x64-gnunpm:@swc/core-linux-x64-gnu
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-linux-x64-muslnpm:@swc/core-linux-x64-musl
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-win32-arm64-msvcnpm:@swc/core-win32-arm64-msvc
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-win32-ia32-msvcnpm:@swc/core-win32-ia32-msvc
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-win32-x64-msvcnpm:@swc/core-win32-x64-msvc
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/counternpm:@swc/counter
1 Vorkommen0.1.3
Apache-2.0
npm@swc/typesnpm:@swc/types
1 Vorkommen0.1.23
Apache-2.0
npm@types/command-line-argsnpm:@types/command-line-args
1 Vorkommen5.2.0
MIT
npm@types/command-line-usagenpm:@types/command-line-usage
1 Vorkommen5.0.2
MIT
npm@types/estreenpm:@types/estree
1 Vorkommen1.0.8
MIT
npm@types/flatbuffersnpm:@types/flatbuffers
1 Vorkommen2.0.1
MIT
npm@types/nodenpm:@types/node
2 Vorkommen18.7.23 · 22.16.5
MIT
npm@types/pad-leftnpm:@types/pad-left
1 Vorkommen2.1.1
MIT
npm@types/prop-typesnpm:@types/prop-types
1 Vorkommen15.7.15
MIT
npm@types/reactnpm:@types/react
1 Vorkommen18.3.23
MIT
npm@types/react-domnpm:@types/react-dom
1 Vorkommen18.3.7
MIT
npm@vitejs/plugin-react-swcnpm:@vitejs/plugin-react-swc
1 Vorkommen3.11.0
MIT
pypiaffinepypi:affine
1 Vorkommen2.4.0
non-standard
pypiaistudio-sdkpypi:aistudio-sdk
1 Vorkommen0.3.8
Nicht gemeldet
pypialtairpypi:altair
2 Vorkommen5.5.0 · 6.0.0
non-standard
pypiannotated-docpypi:annotated-doc
1 Vorkommen0.0.4
MIT
pypiannotated-typespypi:annotated-types
1 Vorkommen0.7.0
MIT
npmansi-stylesnpm:ansi-styles
1 Vorkommen3.2.1
MIT
pypianyiopypi:anyio
1 Vorkommen4.13.0
MIT
npmapache-arrownpm:apache-arrow
1 Vorkommen11.0.0
Apache-2.0
npmarray-backnpm:array-back
2 Vorkommen3.1.0 · 4.0.2
MIT
pypiattrspypi:attrs
2 Vorkommen25.3.0 · 26.1.0
MIT
pypibanditpypi:bandit
1 Vorkommen1.7.5
Apache-2.0
pypibce-python-sdkpypi:bce-python-sdk
1 Vorkommen0.9.68
Apache-2.0
pypiblinkerpypi:blinker
2 Vorkommen1.9.0
MIT
pypicachetoolspypi:cachetools
2 Vorkommen6.2.0 · 7.0.5
MIT
pypicfgvpypi:cfgv
1 Vorkommen3.4.0
MIT
npmchalknpm:chalk
1 Vorkommen2.4.2
MIT
pypichardetpypi:chardet
1 Vorkommen7.4.0.post2
0BSD · non-standard
pypicharset-normalizerpypi:charset-normalizer
2 Vorkommen3.4.3 · 3.4.6
MIT
pypicligjpypi:cligj
1 Vorkommen0.7.2
non-standard
npmcolor-convertnpm:color-convert
1 Vorkommen1.9.3
MIT

Diese Seite zeigt 120 von 266 geordneten Zeilen. Die maschinenlesbare Dossier-Datei bewahrt die vollständige exakte Projektion.

OSV

Zugehörige OSV-Meldungen

GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

1 Repository10. Juni 2026
GHSA-28wg-ghj8-5hjv

nanoid: non-secure generators can loop indefinitely with negative size

2 Repositories10. Aug. 2026
GHSA-2f96-g7mh-g2hx

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

4 Repositories02. Aug. 2026
GHSA-2v37-7h3g-55p8

nanoid: custom generators can loop indefinitely when size is zero

4 Repositories08. Aug. 2026
GHSA-2xpw-w6gg-jr37

urllib3 streaming API improperly handles highly compressed data

13 Repositories07. Juli 2026
GHSA-38jv-5279-wg99

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

13 Repositories07. Juli 2026
GHSA-3f7w-8rr8-f37f

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

4 Repositories08. Aug. 2026
GHSA-3j69-69wj-xqx2

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

5 Repositories18. Juli 2026
GHSA-3rp5-jjmw-4wv2

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

4 Repositories04. Aug. 2026
GHSA-3v7f-55p6-f55p

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

2 Repositories28. März 2026
GHSA-3x9g-8vmp-wqvf

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

6 Repositories13. Juli 2026
GHSA-45hq-cxwh-f6vc

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

13 Repositories22. Juli 2026
GHSA-48p4-8xcf-vxj5

urllib3 does not control redirects in browsers and Node.js

7 Repositories07. Juli 2026
GHSA-4gmw-gg2m-w46p

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

4 Repositories09. Aug. 2026
GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

2 Repositories09. Apr. 2026
GHSA-4x4j-2g7c-83w6

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

13 Repositories22. Juli 2026
GHSA-5239-wwwm-4pmq

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

13 Repositories13. Juli 2026
GHSA-539m-9xh6-q6rr

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

4 Repositories08. Aug. 2026
GHSA-597g-3phw-6986

virtualenv Has TOCTOU Vulnerabilities in Directory Creation

6 Repositories07. Juli 2026
GHSA-5rjg-fvgr-3xxf

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

3 Repositories11. Mai 2026
GHSA-5x94-69rx-g8h2

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

13 Repositories22. Juli 2026
GHSA-5xmw-vc9v-4wf2

Pillow has a heap buffer overflow with nested list coordinates

10 Repositories13. Juli 2026
GHSA-62p4-gmf7-7g93

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

13 Repositories23. Juli 2026
GHSA-6497-prx7-gpmq

geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure

1 Repository10. Juni 2026
GHSA-65pc-fj4g-8rjx

Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix

17 Repositories08. Juli 2026
GHSA-67mh-4wv8-2f99

esbuild enables any website to send any requests to the development server and read the response

1 Repository04. Feb. 2026
GHSA-6g55-p6wh-862q

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

2 Repositories28. Juli 2026
GHSA-6p8h-3wgx-97gf

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

4 Repositories25. Juli 2026
GHSA-6r8x-57c9-28j4

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

13 Repositories22. Juli 2026
GHSA-6w46-j5rx-g56g

pytest has vulnerable tmpdir handling

6 Repositories07. Juli 2026
GHSA-7545-fcxq-7j24

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

4 Repositories13. Juli 2026
GHSA-768j-98cg-p3fv

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

6 Repositories07. Juli 2026
GHSA-78cv-mqj4-43f7

Tornado has incomplete validation of cookie attributes

6 Repositories13. Juli 2026
GHSA-7cx3-6m66-7c5m

Tornado vulnerable to excessive logging caused by malformed multipart form data

2 Repositories07. Juli 2026
GHSA-7gcm-g887-7qv7

protobuf affected by a JSON recursion depth bypass

10 Repositories07. Juli 2026
GHSA-7p48-42j8-8846

Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)

1 Repository13. Juli 2026
GHSA-8qvm-5x2c-j2w7

protobuf-python has a potential Denial of Service issue

3 Repositories07. Juli 2026
GHSA-8v84-f9pq-wr9x

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

13 Repositories22. Juli 2026
GHSA-93m4-6634-74q7

vite allows server.fs.deny bypass via backslash on Windows

1 Repository04. Feb. 2026
GHSA-94p4-4cq8-9g67

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

4 Repositories25. Juli 2026
GHSA-956x-8gvw-wg5v

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

4 Repositories02. Aug. 2026
GHSA-9hjg-9r4m-mvj7

Requests vulnerable to .netrc credentials leak via malicious URLs

7 Repositories07. Juli 2026
GHSA-9hw9-ch79-4vh6

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

13 Repositories22. Juli 2026
GHSA-9rj7-rf2p-w77r

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

4 Repositories09. Aug. 2026
GHSA-9wx4-h78v-vm56

Requests `Session` object does not verify requests after making first request with verify=False

1 Repository07. Juli 2026
GHSA-c2c7-rcm5-vvqj

Picomatch has a ReDoS vulnerability via extglob quantifiers

2 Repositories28. März 2026
GHSA-c38f-wx89-p2xg

UltraJSON has a Memory Leak in ujson.dump() on Write Failure

5 Repositories13. Juli 2026
GHSA-c8rr-9gxc-jprv

UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop

4 Repositories13. Juli 2026
Interpretationsgrenze

Exakte Identitäten hinein, klare Grenzen hinaus

Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.

Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.

i6eal (2026): SmartPlanAI Anwendung – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 13. Aug. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-10162/

So liest du dieses Dossier

Belegt dieses Repository-Dossier einen Betrieb?
Nein. Es dokumentiert veröffentlichte Abhängigkeiten an einem beobachteten Commit – keine eingesetzte Umgebung.
Warum sind exakte Versionen erforderlich?
OSV- und Registermetadaten lassen sich nur mit einem beobachteten paket@version-Tupel reproduzierbar verknüpfen. Der Collector ersetzt einen Versionsbereich nie durch das neueste Release.
Bedeutet eine fehlende Zeile, dass die Abhängigkeit nicht existiert?
Nein. Sie bedeutet nur „in den begrenzten Dateien und am Repository-Prüfpunkt nicht beobachtet“. Unvollständige Bäume und Parserfehler bleiben ausdrücklich sichtbar.

Du brauchst einen dauerhaften Abhängigkeitsevidenzpfad für eine andere öffentliche Code-Kohorte?

Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.

Datenprojekt besprechenAlle Tools ansehen