uba-ki-lab/gsa-extractionDieses Dossier bewahrt 193 exakte Komponentenvorkommen aus 1 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.
Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.
Projekt-ID + Commit-SHA + exakter EvidenzpfadJede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.
sha256:766ab3a9e501607f926b430b6937368e9157d2bb2417294c81529c0b0de9999apypi:transformers4.53.126 zurückgegebene OSV-Meldungenpypi:litellm1.73.6.post123 zurückgegebene OSV-Meldungenpypi:torch2.7.123 zurückgegebene OSV-Meldungenpypi:datasets3.6.01 zurückgegebene OSV-Meldungpypi:dspy2.6.271 zurückgegebene OSV-Meldungpypi:scikit-learn1.7.01 zurückgegebene OSV-Meldungpypi:openai1.93.0pypi:sentence-transformers5.0.0pypi:tokenizers0.21.2pypi:tiktoken0.9.0pypi:nltk3.9.147 zurückgegebene OSV-Meldungenpypi:aiohttp3.12.1333 zurückgegebene OSV-Meldungenpypi:gitpython3.1.4429 zurückgegebene OSV-Meldungenpypi:mlflow3.1.126 zurückgegebene OSV-Meldungenpypi:pillow11.3.020 zurückgegebene OSV-Meldungenpypi:tornado6.5.113 zurückgegebene OSV-Meldungenpypi:starlette0.46.28 zurückgegebene OSV-Meldungenpypi:pip25.1.17 zurückgegebene OSV-Meldungenpypi:urllib32.5.07 zurückgegebene OSV-Meldungenpypi:sqlparse0.5.36 zurückgegebene OSV-Meldungenpypi:werkzeug3.1.36 zurückgegebene OSV-Meldungenpypi:pyasn10.6.15 zurückgegebene OSV-Meldungenpypi:jinja23.1.64 zurückgegebene OSV-Meldungenpypi:ujson5.10.04 zurückgegebene OSV-Meldungenpypi:requests2.32.43 zurückgegebene OSV-Meldungenpypi:setuptools80.9.03 zurückgegebene OSV-Meldungenpypi:anyio4.9.02 zurückgegebene OSV-Meldungenpypi:filelock3.18.02 zurückgegebene OSV-Meldungenpypi:mako1.3.102 zurückgegebene OSV-Meldungenpypi:protobuf6.31.12 zurückgegebene OSV-Meldungenpypi:certifi2025.6.151 zurückgegebene OSV-Meldungpypi:click8.2.11 zurückgegebene OSV-Meldungpypi:diskcache5.6.31 zurückgegebene OSV-Meldungpypi:flask3.1.11 zurückgegebene OSV-Meldungpypi:fonttools4.58.51 zurückgegebene OSV-Meldungpypi:h110.16.01 zurückgegebene OSV-Meldungpypi:hydra-core1.3.21 zurückgegebene OSV-Meldungpypi:idna3.101 zurückgegebene OSV-Meldungpypi:json-repair0.47.61 zurückgegebene OSV-Meldungpypi:jupyter-core5.8.11 zurückgegebene OSV-Meldungpypi:pyarrow20.0.01 zurückgegebene OSV-Meldungpypi:pygments2.19.21 zurückgegebene OSV-Meldungpypi:python-dotenv1.1.11 zurückgegebene OSV-Meldungpypi:tqdm4.67.11 zurückgegebene OSV-Meldungpypi:absl-py2.3.1pypi:aiohappyeyeballs2.6.1pypi:aiosignal1.4.0pypi:alembic1.16.2pypi:annotated-types0.7.0pypi:antlr4-python3-runtime4.9.3pypi:appnope0.1.4pypi:argilla2.8.0pypi:asttokens3.0.0pypi:async-timeout5.0.1pypi:asyncer0.0.8pypi:attrs25.3.0pypi:backoff2.2.1pypi:blinker1.9.0pypi:cachetools5.5.2pypi:cffi1.17.1pypi:charset-normalizer3.4.2pypi:cloudpickle3.1.1pypi:colorama0.4.6pypi:colorlog6.9.0pypi:comm0.2.2pypi:contourpy1.3.2pypi:cycler0.12.1pypi:databricks-sdk0.57.0pypi:debugpy1.8.14pypi:decorator5.2.1pypi:deprecated1.2.18pypi:dill0.3.8pypi:distro1.9.0pypi:docker7.1.0pypi:evaluate0.4.4pypi:exceptiongroup1.3.0pypi:executing2.2.0pypi:fastapi0.115.14pypi:frozenlist1.7.0pypi:fsspec2025.3.0pypi:gitdb4.0.12pypi:google-auth2.40.3pypi:graphene3.4.3pypi:graphql-core3.2.6pypi:graphql-relay3.2.0pypi:greenlet3.2.3pypi:gunicorn23.0.0pypi:hf-xet1.1.5pypi:httpcore1.0.9pypi:httpx0.28.1pypi:huggingface-hub0.33.2pypi:importlib-metadata8.7.0pypi:ipykernel6.29.5pypi:ipython8.37.0 · 9.3.0pypi:ipython-pygments-lexers1.1.1pypi:itsdangerous2.2.0pypi:jedi0.19.2pypi:jiter0.10.0pypi:joblib1.5.1pypi:jsonschema4.24.0pypi:jsonschema-specifications2025.4.1pypi:jupyter-client8.6.3pypi:kiwisolver1.4.8pypi:magicattr0.1.6pypi:markdown-it-py3.0.0pypi:markupsafe3.0.2pypi:matplotlib3.10.3pypi:matplotlib-inline0.1.7pypi:mdurl0.1.2pypi:mlflow-skinny3.1.1pypi:mpmath1.3.0pypi:multidict6.6.3pypi:multiprocess0.70.16pypi:nest-asyncio1.6.0pypi:networkx3.4.2 · 3.5pypi:numpy2.2.6 · 2.3.1pypi:nvidia-cublas-cu1212.6.4.1pypi:nvidia-cuda-cupti-cu1212.6.80pypi:nvidia-cuda-nvrtc-cu1212.6.77pypi:nvidia-cuda-runtime-cu1212.6.77Diese Seite zeigt 120 von 189 geordneten Zeilen. Die maschinenlesbare Dossier-Datei bewahrt die vollständige exakte Projektion.
Certifi removes GLOBALTRUST root certificate
10. Sept. 2026sqlparse: formatting list of tuples leads to denial of service
10. Sept. 2026GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
08. Sept. 2026HuggingFace transformers vulnerable to remote code execution
10. Sept. 2026Werkzeug safe_join() allows Windows special device names
10. Sept. 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
10. Sept. 2026MLflow: trace API endpoints lack proper authorization validators
19. Aug. 2026Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
10. Sept. 2026GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
23. Sept. 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
10. Sept. 2026Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
10. Sept. 2026Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
10. Sept. 2026AIOHTTP has CRLF injection through multipart part content type header construction
10. Sept. 2026urllib3 streaming API improperly handles highly compressed data
25. Sept. 2026Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
10. Sept. 2026sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
10. Sept. 2026PyTorch susceptible to local Denial of Service
10. Sept. 2026Transformers is vulnerable to ReDoS attack through its DonutProcessor class
10. Sept. 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10. Sept. 2026GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
10. Sept. 2026NLTK: Corpus Reader Sandbox Bypass
08. Sept. 2026NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
02. Sept. 2026NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
08. Sept. 2026UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
10. Sept. 2026GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
17. Sept. 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
10. Sept. 2026GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
23. Sept. 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
10. Sept. 2026MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
13. Juli 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10. Sept. 2026NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
10. Sept. 2026MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
10. Sept. 2026urllib3 does not control redirects in browsers and Node.js
10. Sept. 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
10. Sept. 2026LiteLLM: Local file read via request-supplied OIDC file references
10. Sept. 2026GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
10. Sept. 2026LiteLLM: MCP Proxy Has Improper Authentication
11. Sept. 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
10. Sept. 2026Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
10. Sept. 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10. Sept. 2026mlflow Creates of Temporary File in Directory with Insecure Permissions
10. Sept. 2026pip's fallback tar extraction doesn't check symbolic links point to extraction directory
10. Sept. 2026LiteLLM: Authentication Bypass via Host Header Injection
10. Sept. 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10. Sept. 2026GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
10. Sept. 2026LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
10. Sept. 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07. Aug. 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
10. Sept. 2026Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.
Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.i6eal (2026): GSA Extraction – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 30. Sept. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-5530/
Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.
Diese Tools passen thematisch dazu.