← Zurück zum KI-AbhängigkeitsatlasExaktes Repository-Lieferkettendossier

SmartPlanAI Anwendung

sh/digitalhub-sh/landesprogramm-offene-innovationen/ki-bauleitplaene/smartplanai-anwendung
npm · pypi

Dieses Dossier bewahrt 318 exakte Komponentenvorkommen aus 3 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.

opencode:101621d70807d48a8Projekt-ID + Commit-SHA + exakter Evidenzpfad

Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.

Projekt-ID + Commit-SHA + exakter Evidenzpfad
318exakte Komponentenvorkommen
266Paketidentitäten
3Evidenzdateien
121zurückgegebene OSV-Meldungen
Exakte veröffentlichte Evidenz

Dateien, die Abhängigkeiten dieses Repositories auflösen

Jede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.

Evidenzpfadblp_streamlit_pipeline/src/ext/streamlit-draw-image-mask/draw_image_mask/draw_image_mask/frontend/package-lock.jsonsha256:d6cf494bd944eff796a59b32b36c8214816e3be6639d5c2ea67893310aa39322
Format
npm-lock
Parserstatus
parsed
Aufgelöste Komponenten
123
Exakte Quelle öffnen ↗
Evidenzpfadblp_streamlit_pipeline/src/ext/streamlit-draw-image-mask/poetry.locksha256:834ae2be07a53839d9a28b3e1f69e45e947515a00364ef07871b6fc47c379933
Format
poetry-lock
Parserstatus
parsed
Aufgelöste Komponenten
78
Exakte Quelle öffnen ↗
Evidenzpfadpoetry.locksha256:aeab690097e8e006cb4680cb53d452b805b943ab2091762607ff4d493cc71549
Format
poetry-lock
Parserstatus
parsed
Aufgelöste Komponenten
117
Exakte Quelle öffnen ↗
Beobachtete Beziehungen

Paketidentitäten an diesem Commit

pypiOpenCVpypi:opencv-python
2 Vorkommen4.12.0.88 · 4.13.0.92
Apache-2.0
→
pypigitpythonpypi:gitpython
2 Vorkommen3.1.45 · 3.1.46
BSD-3-Clause29 zurückgegebene OSV-Meldungen
pypipillowpypi:pillow
2 Vorkommen11.3.0 · 12.1.1
HPND · MIT-CMU20 zurückgegebene OSV-Meldungen
→
pypitornadopypi:tornado
2 Vorkommen6.5.2 · 6.5.5
Apache-2.013 zurückgegebene OSV-Meldungen
→
pypiurllib3pypi:urllib3
2 Vorkommen2.5.0 · 2.6.3
MIT7 zurückgegebene OSV-Meldungen
→
npmvitenpm:vite
1 Vorkommen6.3.5
MIT7 zurückgegebene OSV-Meldungen
pypijinja2pypi:jinja2
2 Vorkommen3.1.6
BSD-3-Clause · non-standard4 zurückgegebene OSV-Meldungen
→
npmpostcssnpm:postcss
1 Vorkommen8.5.6
MIT4 zurückgegebene OSV-Meldungen
pypiujsonpypi:ujson
1 Vorkommen5.12.0
BSD-3-Clause · BSD-3-Clause AND TCL · TCL4 zurückgegebene OSV-Meldungen
npmnanoidnpm:nanoid
1 Vorkommen3.3.11
MIT3 zurückgegebene OSV-Meldungen
pypirequestspypi:requests
2 Vorkommen2.32.5 · 2.33.1
Apache-2.03 zurückgegebene OSV-Meldungen
→
pypisetuptoolspypi:setuptools
2 Vorkommen80.9.0 · 82.0.1
MIT3 zurückgegebene OSV-Meldungen
→
pypianyiopypi:anyio
1 Vorkommen4.13.0
MIT2 zurückgegebene OSV-Meldungen
→
pypifilelockpypi:filelock
2 Vorkommen3.19.1 · 3.25.2
MIT · Unlicense2 zurückgegebene OSV-Meldungen
→
npmpicomatchnpm:picomatch
1 Vorkommen4.0.3
MIT2 zurückgegebene OSV-Meldungen
pypiprotobufpypi:protobuf
2 Vorkommen6.32.0 · 6.33.6
BSD-3-Clause2 zurückgegebene OSV-Meldungen
→
pypistreamlitpypi:streamlit
2 Vorkommen1.49.0 · 1.55.0
Apache-2.02 zurückgegebene OSV-Meldungen
pypicertifipypi:certifi
2 Vorkommen2025.8.3 · 2026.2.25
MPL-2.01 zurückgegebene OSV-Meldung
→
pypiclickpypi:click
2 Vorkommen8.1.8 · 8.3.1
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
→
npmesbuildnpm:esbuild
1 Vorkommen0.25.8
MIT1 zurückgegebene OSV-Meldung
pypifonttoolspypi:fonttools
1 Vorkommen4.62.1
MIT1 zurückgegebene OSV-Meldung
→
pypigeopandaspypi:geopandas
1 Vorkommen1.1.3
BSD-3-Clause1 zurückgegebene OSV-Meldung
pypih11pypi:h11
1 Vorkommen0.16.0
MIT1 zurückgegebene OSV-Meldung
→
pypiidnapypi:idna
2 Vorkommen3.10 · 3.11
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
→
pypipyarrowpypi:pyarrow
2 Vorkommen21.0.0 · 23.0.1
Apache-2.0 · non-standard1 zurückgegebene OSV-Meldung
→
pypipycryptodomepypi:pycryptodome
1 Vorkommen3.23.0
non-standard1 zurückgegebene OSV-Meldung
pypipygmentspypi:pygments
2 Vorkommen2.19.2 · 2.20.0
BSD-2-Clause1 zurückgegebene OSV-Meldung
→
pypipytestpypi:pytest
1 Vorkommen8.3.2
MIT1 zurückgegebene OSV-Meldung
npmrollupnpm:rollup
1 Vorkommen4.46.1
MIT1 zurückgegebene OSV-Meldung
pypitqdmpypi:tqdm
1 Vorkommen4.67.3
MIT AND MPL-2.01 zurückgegebene OSV-Meldung
→
pypivirtualenvpypi:virtualenv
1 Vorkommen20.34.0
MIT1 zurückgegebene OSV-Meldung
npm@esbuild/aix-ppc64npm:@esbuild/aix-ppc64
1 Vorkommen0.25.8
MIT
npm@esbuild/android-armnpm:@esbuild/android-arm
1 Vorkommen0.25.8
MIT
npm@esbuild/android-arm64npm:@esbuild/android-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/android-x64npm:@esbuild/android-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/darwin-arm64npm:@esbuild/darwin-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/darwin-x64npm:@esbuild/darwin-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/freebsd-arm64npm:@esbuild/freebsd-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/freebsd-x64npm:@esbuild/freebsd-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-armnpm:@esbuild/linux-arm
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-arm64npm:@esbuild/linux-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-ia32npm:@esbuild/linux-ia32
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-loong64npm:@esbuild/linux-loong64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-mips64elnpm:@esbuild/linux-mips64el
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-ppc64npm:@esbuild/linux-ppc64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-riscv64npm:@esbuild/linux-riscv64
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-s390xnpm:@esbuild/linux-s390x
1 Vorkommen0.25.8
MIT
npm@esbuild/linux-x64npm:@esbuild/linux-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/netbsd-arm64npm:@esbuild/netbsd-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/netbsd-x64npm:@esbuild/netbsd-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/openbsd-arm64npm:@esbuild/openbsd-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/openbsd-x64npm:@esbuild/openbsd-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/openharmony-arm64npm:@esbuild/openharmony-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/sunos-x64npm:@esbuild/sunos-x64
1 Vorkommen0.25.8
MIT
npm@esbuild/win32-arm64npm:@esbuild/win32-arm64
1 Vorkommen0.25.8
MIT
npm@esbuild/win32-ia32npm:@esbuild/win32-ia32
1 Vorkommen0.25.8
MIT
npm@esbuild/win32-x64npm:@esbuild/win32-x64
1 Vorkommen0.25.8
MIT
npm@rolldown/pluginutilsnpm:@rolldown/pluginutils
1 Vorkommen1.0.0-beta.27
MIT
npm@rollup/rollup-android-arm-eabinpm:@rollup/rollup-android-arm-eabi
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-android-arm64npm:@rollup/rollup-android-arm64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-darwin-arm64npm:@rollup/rollup-darwin-arm64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-darwin-x64npm:@rollup/rollup-darwin-x64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-freebsd-arm64npm:@rollup/rollup-freebsd-arm64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-freebsd-x64npm:@rollup/rollup-freebsd-x64
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-arm-gnueabihfnpm:@rollup/rollup-linux-arm-gnueabihf
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-arm-musleabihfnpm:@rollup/rollup-linux-arm-musleabihf
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-arm64-gnunpm:@rollup/rollup-linux-arm64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-arm64-muslnpm:@rollup/rollup-linux-arm64-musl
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-loongarch64-gnunpm:@rollup/rollup-linux-loongarch64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-ppc64-gnunpm:@rollup/rollup-linux-ppc64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-riscv64-gnunpm:@rollup/rollup-linux-riscv64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-riscv64-muslnpm:@rollup/rollup-linux-riscv64-musl
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-s390x-gnunpm:@rollup/rollup-linux-s390x-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-x64-gnunpm:@rollup/rollup-linux-x64-gnu
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-linux-x64-muslnpm:@rollup/rollup-linux-x64-musl
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-win32-arm64-msvcnpm:@rollup/rollup-win32-arm64-msvc
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-win32-ia32-msvcnpm:@rollup/rollup-win32-ia32-msvc
1 Vorkommen4.46.1
MIT
npm@rollup/rollup-win32-x64-msvcnpm:@rollup/rollup-win32-x64-msvc
1 Vorkommen4.46.1
MIT
npm@swc/corenpm:@swc/core
1 Vorkommen1.13.3
Apache-2.0
npm@swc/core-darwin-arm64npm:@swc/core-darwin-arm64
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-darwin-x64npm:@swc/core-darwin-x64
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-linux-arm-gnueabihfnpm:@swc/core-linux-arm-gnueabihf
1 Vorkommen1.13.3
Apache-2.0
npm@swc/core-linux-arm64-gnunpm:@swc/core-linux-arm64-gnu
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-linux-arm64-muslnpm:@swc/core-linux-arm64-musl
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-linux-x64-gnunpm:@swc/core-linux-x64-gnu
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-linux-x64-muslnpm:@swc/core-linux-x64-musl
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-win32-arm64-msvcnpm:@swc/core-win32-arm64-msvc
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-win32-ia32-msvcnpm:@swc/core-win32-ia32-msvc
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/core-win32-x64-msvcnpm:@swc/core-win32-x64-msvc
1 Vorkommen1.13.3
Apache-2.0 AND MIT
npm@swc/counternpm:@swc/counter
1 Vorkommen0.1.3
Apache-2.0
npm@swc/typesnpm:@swc/types
1 Vorkommen0.1.23
Apache-2.0
npm@types/command-line-argsnpm:@types/command-line-args
1 Vorkommen5.2.0
MIT
npm@types/command-line-usagenpm:@types/command-line-usage
1 Vorkommen5.0.2
MIT
npm@types/estreenpm:@types/estree
1 Vorkommen1.0.8
MIT
npm@types/flatbuffersnpm:@types/flatbuffers
1 Vorkommen2.0.1
MIT
npm@types/nodenpm:@types/node
2 Vorkommen18.7.23 · 22.16.5
MIT
npm@types/pad-leftnpm:@types/pad-left
1 Vorkommen2.1.1
MIT
npm@types/prop-typesnpm:@types/prop-types
1 Vorkommen15.7.15
MIT
npm@types/reactnpm:@types/react
1 Vorkommen18.3.23
MIT
npm@types/react-domnpm:@types/react-dom
1 Vorkommen18.3.7
MIT
npm@vitejs/plugin-react-swcnpm:@vitejs/plugin-react-swc
1 Vorkommen3.11.0
MIT
pypiaffinepypi:affine
1 Vorkommen2.4.0
non-standard
pypiaistudio-sdkpypi:aistudio-sdk
1 Vorkommen0.3.8
Nicht gemeldet
pypialtairpypi:altair
2 Vorkommen5.5.0 · 6.0.0
non-standard
pypiannotated-docpypi:annotated-doc
1 Vorkommen0.0.4
MIT
pypiannotated-typespypi:annotated-types
1 Vorkommen0.7.0
MIT
npmansi-stylesnpm:ansi-styles
1 Vorkommen3.2.1
MIT
npmapache-arrownpm:apache-arrow
1 Vorkommen11.0.0
Apache-2.0
npmarray-backnpm:array-back
2 Vorkommen3.1.0 · 4.0.2
MIT
pypiattrspypi:attrs
2 Vorkommen25.3.0 · 26.1.0
MIT
pypibanditpypi:bandit
1 Vorkommen1.7.5
Apache-2.0
pypibce-python-sdkpypi:bce-python-sdk
1 Vorkommen0.9.68
Apache-2.0
pypiblinkerpypi:blinker
2 Vorkommen1.9.0
MIT
pypicachetoolspypi:cachetools
2 Vorkommen6.2.0 · 7.0.5
MIT
pypicfgvpypi:cfgv
1 Vorkommen3.4.0
MIT
npmchalknpm:chalk
1 Vorkommen2.4.2
MIT
pypichardetpypi:chardet
1 Vorkommen7.4.0.post2
0BSD · non-standard
pypicharset-normalizerpypi:charset-normalizer
2 Vorkommen3.4.3 · 3.4.6
MIT
pypicligjpypi:cligj
1 Vorkommen0.7.2
non-standard
npmcolor-convertnpm:color-convert
1 Vorkommen1.9.3
MIT

Diese Seite zeigt 120 von 266 geordneten Zeilen. Die maschinenlesbare Dossier-Datei bewahrt die vollständige exakte Projektion.

OSV

Zugehörige OSV-Meldungen

GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

1 Repository10. Sept. 2026
GHSA-284h-m62q-gf8w

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

6 Repositories08. Sept. 2026
GHSA-28wg-ghj8-5hjv

nanoid: non-secure generators can loop indefinitely with negative size

3 Repositories10. Sept. 2026
GHSA-2f96-g7mh-g2hx

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

6 Repositories23. Sept. 2026
GHSA-2v37-7h3g-55p8

nanoid: custom generators can loop indefinitely when size is zero

4 Repositories10. Sept. 2026
GHSA-2xpw-w6gg-jr37

urllib3 streaming API improperly handles highly compressed data

16 Repositories25. Sept. 2026
→
GHSA-38jv-5279-wg99

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

16 Repositories10. Sept. 2026
→
GHSA-3f7w-8rr8-f37f

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

6 Repositories10. Sept. 2026
GHSA-3j69-69wj-xqx2

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

5 Repositories10. Sept. 2026
GHSA-3rp5-jjmw-4wv2

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

6 Repositories17. Sept. 2026
GHSA-3v7f-55p6-f55p

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

3 Repositories10. Sept. 2026
GHSA-3wxw-xv34-2frg

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

6 Repositories23. Sept. 2026
GHSA-3x9g-8vmp-wqvf

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

9 Repositories10. Sept. 2026
GHSA-45hq-cxwh-f6vc

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

17 Repositories10. Sept. 2026
→
GHSA-48p4-8xcf-vxj5

urllib3 does not control redirects in browsers and Node.js

8 Repositories10. Sept. 2026
GHSA-4gmw-gg2m-w46p

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

6 Repositories10. Sept. 2026
GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

3 Repositories10. Sept. 2026
GHSA-4x4j-2g7c-83w6

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

17 Repositories10. Sept. 2026
→
GHSA-5239-wwwm-4pmq

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

15 Repositories10. Sept. 2026
GHSA-539m-9xh6-q6rr

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

6 Repositories10. Sept. 2026
GHSA-597g-3phw-6986

virtualenv Has TOCTOU Vulnerabilities in Directory Creation

7 Repositories10. Sept. 2026
GHSA-5p39-cfhj-2xmp

AnyIO process-pool workers can block indefinitely on undrained stderr

16 Repositories18. Sept. 2026
→
GHSA-5rjg-fvgr-3xxf

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

4 Repositories10. Sept. 2026
GHSA-5x94-69rx-g8h2

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

17 Repositories10. Sept. 2026
→
GHSA-5xmw-vc9v-4wf2

Pillow has a heap buffer overflow with nested list coordinates

12 Repositories10. Sept. 2026
GHSA-5xxx-qhh7-9287

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

6 Repositories08. Sept. 2026
GHSA-62p4-gmf7-7g93

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

17 Repositories10. Sept. 2026
→
GHSA-6497-prx7-gpmq

geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure

2 Repositories10. Juni 2026
GHSA-65pc-fj4g-8rjx

Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix

21 Repositories10. Sept. 2026
→
GHSA-67mh-4wv8-2f99

esbuild enables any website to send any requests to the development server and read the response

1 Repository10. Sept. 2026
GHSA-6g55-p6wh-862q

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

3 Repositories10. Sept. 2026
GHSA-6p8h-3wgx-97gf

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

6 Repositories10. Sept. 2026
GHSA-6r8x-57c9-28j4

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

17 Repositories10. Sept. 2026
→
GHSA-6w46-j5rx-g56g

pytest has vulnerable tmpdir handling

7 Repositories10. Sept. 2026
GHSA-7545-fcxq-7j24

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

6 Repositories10. Sept. 2026
GHSA-768j-98cg-p3fv

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

7 Repositories10. Sept. 2026
GHSA-7833-fr7j-v32q

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

6 Repositories23. Sept. 2026
GHSA-78cv-mqj4-43f7

Tornado has incomplete validation of cookie attributes

9 Repositories10. Sept. 2026
GHSA-7cx3-6m66-7c5m

Tornado vulnerable to excessive logging caused by malformed multipart form data

2 Repositories10. Sept. 2026
GHSA-7gcm-g887-7qv7

protobuf affected by a JSON recursion depth bypass

13 Repositories10. Sept. 2026
GHSA-7p48-42j8-8846

Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)

3 Repositories13. Juli 2026
GHSA-82r6-8w77-94w6

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

16 Repositories18. Sept. 2026
GHSA-8423-8fgw-73vq

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

10 Repositories16. Sept. 2026
GHSA-8mcc-hrx5-hvxc

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

6 Repositories08. Sept. 2026
GHSA-8qvm-5x2c-j2w7

protobuf-python has a potential Denial of Service issue

3 Repositories10. Sept. 2026
GHSA-8v84-f9pq-wr9x

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

17 Repositories10. Sept. 2026
→
GHSA-93m4-6634-74q7

vite allows server.fs.deny bypass via backslash on Windows

1 Repository10. Sept. 2026
GHSA-94p4-4cq8-9g67

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

6 Repositories24. Sept. 2026
Interpretationsgrenze

Exakte Identitäten hinein, klare Grenzen hinaus

Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.

Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.

i6eal (2026): SmartPlanAI Anwendung – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 30. Sept. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-10162/

So liest du dieses Dossier

Belegt dieses Repository-Dossier einen Betrieb?
Nein. Es dokumentiert veröffentlichte Abhängigkeiten an einem beobachteten Commit – keine eingesetzte Umgebung.
Warum sind exakte Versionen erforderlich?
OSV- und Registermetadaten lassen sich nur mit einem beobachteten paket@version-Tupel reproduzierbar verknüpfen. Der Collector ersetzt einen Versionsbereich nie durch das neueste Release.
Bedeutet eine fehlende Zeile, dass die Abhängigkeit nicht existiert?
Nein. Sie bedeutet nur „in den begrenzten Dateien und am Repository-Prüfpunkt nicht beobachtet“. Unvollständige Bäume und Parserfehler bleiben ausdrücklich sichtbar.

Du brauchst einen dauerhaften Abhängigkeitsevidenzpfad für eine andere öffentliche Code-Kohorte?

Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.

Datenprojekt besprechenAlle Tools ansehen