uba-ki-lab/ressource-efficient-computer-visionDieses Dossier bewahrt 244 exakte Komponentenvorkommen aus 3 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.
Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.
Projekt-ID + Commit-SHA + exakter EvidenzpfadJede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.
sha256:5ae12d5615c84d40c25d23a8c2e2306ea5f3f1f75a14a27e1c36426ce966c99fsha256:e2f86442aaca182ff71abf8a0d916c515193ed063af29d024bd5365c66c3aa2cpypi:transformers4.57.425 zurückgegebene OSV-Meldungenpypi:torch2.7.1+cpu · 2.9.123 zurückgegebene OSV-Meldungenpypi:codecarbon3.2.1pypi:tokenizers0.22.2pypi:opencv-python4.11.0.86pypi:scikit-learn1.8.0pypi:ultralytics8.3.252pypi:mlflow3.8.123 zurückgegebene OSV-Meldungenpypi:gitpython3.1.4622 zurückgegebene OSV-Meldungenpypi:pillow12.1.020 zurückgegebene OSV-Meldungenpypi:tornado6.5.410 zurückgegebene OSV-Meldungenpypi:cryptography46.0.39 zurückgegebene OSV-Meldungenpypi:starlette0.50.08 zurückgegebene OSV-Meldungenpypi:urllib32.6.37 zurückgegebene OSV-Meldungenpypi:werkzeug3.1.56 zurückgegebene OSV-Meldungenpypi:flask-cors6.0.25 zurückgegebene OSV-Meldungenpypi:pyasn10.6.15 zurückgegebene OSV-Meldungenpypi:jinja23.1.64 zurückgegebene OSV-Meldungenpypi:pymdown-extensions10.21.23 zurückgegebene OSV-Meldungenpypi:requests2.32.53 zurückgegebene OSV-Meldungenpypi:setuptools80.9.03 zurückgegebene OSV-Meldungenpypi:filelock3.20.32 zurückgegebene OSV-Meldungenpypi:mako1.3.102 zurückgegebene OSV-Meldungenpypi:protobuf6.33.42 zurückgegebene OSV-Meldungenpypi:streamlit1.55.02 zurückgegebene OSV-Meldungenpypi:certifi2026.1.41 zurückgegebene OSV-Meldungpypi:click8.3.11 zurückgegebene OSV-Meldungpypi:flask3.1.21 zurückgegebene OSV-Meldungpypi:fonttools4.61.11 zurückgegebene OSV-Meldungpypi:h110.16.01 zurückgegebene OSV-Meldungpypi:idna3.111 zurückgegebene OSV-Meldungpypi:jupyter-core5.9.11 zurückgegebene OSV-Meldungpypi:jwcrypto1.5.61 zurückgegebene OSV-Meldungpypi:marimo0.23.41 zurückgegebene OSV-Meldungpypi:markdown3.101 zurückgegebene OSV-Meldungpypi:pyarrow22.0.01 zurückgegebene OSV-Meldungpypi:pygments2.19.21 zurückgegebene OSV-Meldungpypi:pytest9.0.21 zurückgegebene OSV-Meldungpypi:python-dotenv1.2.11 zurückgegebene OSV-Meldungpypi:sqlparse0.5.51 zurückgegebene OSV-Meldungpypi:tqdm4.67.11 zurückgegebene OSV-Meldungpypi:absl-py2.3.1pypi:addict2.4.0pypi:albucore0.0.24pypi:albumentations2.0.8pypi:alembic1.18.0pypi:altair6.0.0pypi:annotated-doc0.0.4pypi:annotated-types0.7.0pypi:antlr4-python3-runtime4.9.3pypi:anyio4.12.1pypi:appnope0.1.4pypi:arrow1.4.0pypi:asttokens3.0.1pypi:attrs25.4.0pypi:autograd1.8.0pypi:blinker1.9.0pypi:cachetools6.2.4pypi:cffi2.0.0pypi:charset-normalizer3.4.4pypi:cloudpickle3.1.2pypi:colorama0.4.6pypi:colorlog6.10.1pypi:comm0.2.3pypi:contourpy1.3.3pypi:cycler0.12.1pypi:databricks-sdk0.77.0pypi:debugpy1.8.19pypi:decorator5.2.1pypi:docker7.1.0pypi:docutils0.22.4pypi:escnn1.0.11pypi:executing2.2.1pypi:fastapi0.128.0pypi:fief-client0.20.0pypi:fsspec2026.1.0pypi:gitdb4.0.12pypi:google-auth2.47.0pypi:graphene3.4.3pypi:graphql-core3.2.7pypi:graphql-relay3.2.0pypi:greenlet3.3.0pypi:groundingdino-py0.4.0pypi:grpcio1.76.0pypi:gunicorn23.0.0pypi:hf-xet1.2.0pypi:httpcore1.0.9pypi:httpx0.27.2pypi:huey2.6.0pypi:huggingface-hub0.36.0pypi:hydra-core1.3.2pypi:imageio2.37.2pypi:importlib-metadata8.7.1pypi:iniconfig2.3.0pypi:ipykernel7.1.0pypi:ipython9.9.0pypi:ipython-pygments-lexers1.1.1pypi:ipywidgets8.1.8pypi:itsdangerous2.2.0pypi:jedi0.19.2pypi:joblib1.5.3pypi:jsonschema4.26.0pypi:jsonschema-specifications2025.9.1pypi:jupyter-client8.8.0pypi:jupyterlab-widgets3.0.16pypi:jwt1.4.0pypi:kiwisolver1.4.9pypi:lazy-loader0.4pypi:lie-learn0.0.2pypi:lightning-utilities0.15.2pypi:loro1.10.3pypi:markdown-it-py4.0.0pypi:markupsafe3.0.3pypi:matplotlib3.10.8pypi:matplotlib-inline0.2.1pypi:mdurl0.1.2pypi:mlflow-skinny3.8.1pypi:mlflow-tracing3.8.1pypi:mpmath1.3.0pypi:msgspec0.21.1Diese Seite zeigt 120 von 227 geordneten Zeilen. Die maschinenlesbare Dossier-Datei bewahrt die vollständige exakte Projektion.
Certifi removes GLOBALTRUST root certificate
10. Juni 2026sqlparse: formatting list of tuples leads to denial of service
19. Feb. 2026HuggingFace transformers vulnerable to remote code execution
13. Juli 2026Werkzeug safe_join() allows Windows special device names
13. Juli 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
07. Juli 2026GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
02. Aug. 2026Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
07. Juli 2026Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
13. Juli 2026urllib3 streaming API improperly handles highly compressed data
07. Juli 2026Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
07. Juli 2026PyTorch susceptible to local Denial of Service
10. Juni 2026Transformers is vulnerable to ReDoS attack through its DonutProcessor class
07. Juli 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07. Juli 2026GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
08. Aug. 2026GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
04. Aug. 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
13. Juli 2026MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
13. Juli 2026Flask-CORS vulnerable to Improper Handling of Case Sensitivity
07. Juli 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
22. Juli 2026MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
10. Juni 2026urllib3 does not control redirects in browsers and Node.js
07. Juli 2026GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
09. Aug. 2026Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
07. Juli 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
22. Juli 2026mlflow Creates of Temporary File in Directory with Insecure Permissions
07. Juli 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
13. Juli 2026Vulnerable OpenSSL included in cryptography wheels
16. Juni 2026GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
08. Aug. 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07. Aug. 2026Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
07. Juli 2026MLflow: Deterministic sampling in dataset digest enables predictable collisions
23. Juli 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
11. Mai 2026Python-Markdown has an Uncaught Exception
10. Juni 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
22. Juli 2026Pillow has a heap buffer overflow with nested list coordinates
13. Juli 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
23. Juli 2026Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
13. Juli 2026pyasn1 has a DoS vulnerability in decoder
21. Juli 2026MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
13. Juli 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
08. Juli 2026Flask session does not add `Vary: Cookie` header when accessed in some ways
13. Juli 2026HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
13. Juli 2026GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
25. Juli 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
22. Juli 2026Transformers Regular Expression Denial of Service (ReDoS) vulnerability
07. Juli 2026pytest has vulnerable tmpdir handling
07. Juli 2026GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
13. Juli 2026MLflow: unauthenticated access to certain FastAPI routes
13. Juli 2026Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.
Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.i6eal (2026): Ressource Efficient Computer Vision – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 12. Aug. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-10775/
Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.
Diese Tools ergänzen die aktuelle Auswertung.