← Zurück zum KI-AbhängigkeitsatlasExaktes Repository-Lieferkettendossier

GSA Extraction

uba-ki-lab/gsa-extraction
pypi

Dieses Dossier bewahrt 193 exakte Komponentenvorkommen aus 1 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.

opencode:5530f5161e79d3f8Projekt-ID + Commit-SHA + exakter Evidenzpfad

Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.

Projekt-ID + Commit-SHA + exakter Evidenzpfad
193exakte Komponentenvorkommen
189Paketidentitäten
1Evidenzdatei
318zurückgegebene OSV-Meldungen
Exakte veröffentlichte Evidenz

Dateien, die Abhängigkeiten dieses Repositories auflösen

Jede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.

Evidenzpfaduv.locksha256:766ab3a9e501607f926b430b6937368e9157d2bb2417294c81529c0b0de9999a
Format
uv-lock
Parserstatus
parsed
Aufgelöste Komponenten
193
Exakte Quelle öffnen ↗
Beobachtete Beziehungen

Paketidentitäten an diesem Commit

pypiTransformerspypi:transformers
1 Vorkommen4.53.1
Apache-2.026 zurückgegebene OSV-Meldungen
→
pypiLiteLLMpypi:litellm
1 Vorkommen1.73.6.post1
MIT23 zurückgegebene OSV-Meldungen
→
pypiPyTorchpypi:torch
1 Vorkommen2.7.1
BSD-3-Clause23 zurückgegebene OSV-Meldungen
→
pypiHugging Face Datasetspypi:datasets
1 Vorkommen3.6.0
Apache-2.01 zurückgegebene OSV-Meldung
→
pypiDSPypypi:dspy
1 Vorkommen2.6.27
MIT1 zurückgegebene OSV-Meldung
→
pypiscikit-learnpypi:scikit-learn
1 Vorkommen1.7.0
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
→
pypiOpenAI SDKpypi:openai
1 Vorkommen1.93.0
Apache-2.0
→
pypiSentence Transformerspypi:sentence-transformers
1 Vorkommen5.0.0
Apache-2.0
→
pypiHugging Face Tokenizerspypi:tokenizers
1 Vorkommen0.21.2
non-standard
→
pypitiktokenpypi:tiktoken
1 Vorkommen0.9.0
non-standard
→
pypinltkpypi:nltk
1 Vorkommen3.9.1
Apache-2.047 zurückgegebene OSV-Meldungen
pypiaiohttppypi:aiohttp
1 Vorkommen3.12.13
Apache-2.0 · Apache-2.0 AND MIT33 zurückgegebene OSV-Meldungen
→
pypigitpythonpypi:gitpython
1 Vorkommen3.1.44
BSD-3-Clause29 zurückgegebene OSV-Meldungen
pypimlflowpypi:mlflow
1 Vorkommen3.1.1
non-standard26 zurückgegebene OSV-Meldungen
pypipillowpypi:pillow
1 Vorkommen11.3.0
HPND · MIT-CMU20 zurückgegebene OSV-Meldungen
→
pypitornadopypi:tornado
1 Vorkommen6.5.1
Apache-2.013 zurückgegebene OSV-Meldungen
→
pypistarlettepypi:starlette
1 Vorkommen0.46.2
BSD-3-Clause8 zurückgegebene OSV-Meldungen
→
pypipippypi:pip
1 Vorkommen25.1.1
MIT7 zurückgegebene OSV-Meldungen
pypiurllib3pypi:urllib3
1 Vorkommen2.5.0
MIT7 zurückgegebene OSV-Meldungen
→
pypisqlparsepypi:sqlparse
1 Vorkommen0.5.3
non-standard6 zurückgegebene OSV-Meldungen
pypiwerkzeugpypi:werkzeug
1 Vorkommen3.1.3
BSD-3-Clause · non-standard6 zurückgegebene OSV-Meldungen
pypipyasn1pypi:pyasn1
1 Vorkommen0.6.1
BSD-2-Clause5 zurückgegebene OSV-Meldungen
pypijinja2pypi:jinja2
1 Vorkommen3.1.6
BSD-3-Clause · non-standard4 zurückgegebene OSV-Meldungen
→
pypiujsonpypi:ujson
1 Vorkommen5.10.0
BSD-3-Clause · BSD-3-Clause AND TCL · TCL4 zurückgegebene OSV-Meldungen
pypirequestspypi:requests
1 Vorkommen2.32.4
Apache-2.03 zurückgegebene OSV-Meldungen
→
pypisetuptoolspypi:setuptools
1 Vorkommen80.9.0
MIT3 zurückgegebene OSV-Meldungen
→
pypianyiopypi:anyio
1 Vorkommen4.9.0
MIT2 zurückgegebene OSV-Meldungen
→
pypifilelockpypi:filelock
1 Vorkommen3.18.0
MIT · Unlicense2 zurückgegebene OSV-Meldungen
→
pypimakopypi:mako
1 Vorkommen1.3.10
MIT2 zurückgegebene OSV-Meldungen
pypiprotobufpypi:protobuf
1 Vorkommen6.31.1
BSD-3-Clause2 zurückgegebene OSV-Meldungen
→
pypicertifipypi:certifi
1 Vorkommen2025.6.15
MPL-2.01 zurückgegebene OSV-Meldung
→
pypiclickpypi:click
1 Vorkommen8.2.1
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
→
pypidiskcachepypi:diskcache
1 Vorkommen5.6.3
Apache-2.01 zurückgegebene OSV-Meldung
pypiflaskpypi:flask
1 Vorkommen3.1.1
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
pypifonttoolspypi:fonttools
1 Vorkommen4.58.5
MIT1 zurückgegebene OSV-Meldung
→
pypih11pypi:h11
1 Vorkommen0.16.0
MIT1 zurückgegebene OSV-Meldung
→
pypihydra-corepypi:hydra-core
1 Vorkommen1.3.2
MIT1 zurückgegebene OSV-Meldung
pypiidnapypi:idna
1 Vorkommen3.10
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
→
pypijson-repairpypi:json-repair
1 Vorkommen0.47.6
non-standard1 zurückgegebene OSV-Meldung
pypijupyter-corepypi:jupyter-core
1 Vorkommen5.8.1
BSD-3-Clause · non-standard1 zurückgegebene OSV-Meldung
pypipyarrowpypi:pyarrow
1 Vorkommen20.0.0
Apache-2.0 · non-standard1 zurückgegebene OSV-Meldung
→
pypipygmentspypi:pygments
1 Vorkommen2.19.2
BSD-2-Clause1 zurückgegebene OSV-Meldung
→
pypipython-dotenvpypi:python-dotenv
1 Vorkommen1.1.1
BSD-3-Clause1 zurückgegebene OSV-Meldung
→
pypitqdmpypi:tqdm
1 Vorkommen4.67.1
MIT AND MPL-2.01 zurückgegebene OSV-Meldung
→
pypiabsl-pypypi:absl-py
1 Vorkommen2.3.1
Apache-2.0
pypiaiohappyeyeballspypi:aiohappyeyeballs
1 Vorkommen2.6.1
PSF-2.0
pypiaiosignalpypi:aiosignal
1 Vorkommen1.4.0
Apache-2.0
pypialembicpypi:alembic
1 Vorkommen1.16.2
MIT
pypiannotated-typespypi:annotated-types
1 Vorkommen0.7.0
MIT
pypiantlr4-python3-runtimepypi:antlr4-python3-runtime
1 Vorkommen4.9.3
non-standard
pypiappnopepypi:appnope
1 Vorkommen0.1.4
non-standard
pypiargillapypi:argilla
1 Vorkommen2.8.0
Apache-2.0
pypiasttokenspypi:asttokens
1 Vorkommen3.0.0
Apache-2.0
pypiasync-timeoutpypi:async-timeout
1 Vorkommen5.0.1
Apache-2.0
pypiasyncerpypi:asyncer
1 Vorkommen0.0.8
MIT
pypiattrspypi:attrs
1 Vorkommen25.3.0
MIT
pypibackoffpypi:backoff
1 Vorkommen2.2.1
MIT
pypiblinkerpypi:blinker
1 Vorkommen1.9.0
MIT
pypicachetoolspypi:cachetools
1 Vorkommen5.5.2
MIT
pypicffipypi:cffi
1 Vorkommen1.17.1
MIT · MIT-0
pypicharset-normalizerpypi:charset-normalizer
1 Vorkommen3.4.2
MIT
pypicloudpicklepypi:cloudpickle
1 Vorkommen3.1.1
BSD-3-Clause
pypicoloramapypi:colorama
1 Vorkommen0.4.6
non-standard
pypicolorlogpypi:colorlog
1 Vorkommen6.9.0
MIT
pypicommpypi:comm
1 Vorkommen0.2.2
non-standard
pypicontourpypypi:contourpy
1 Vorkommen1.3.2
non-standard
pypicyclerpypi:cycler
1 Vorkommen0.12.1
non-standard
pypidatabricks-sdkpypi:databricks-sdk
1 Vorkommen0.57.0
non-standard
pypidebugpypypi:debugpy
1 Vorkommen1.8.14
MIT
pypidecoratorpypi:decorator
1 Vorkommen5.2.1
BSD-2-Clause · non-standard
pypideprecatedpypi:deprecated
1 Vorkommen1.2.18
MIT
pypidillpypi:dill
1 Vorkommen0.3.8
BSD-3-Clause
pypidistropypi:distro
1 Vorkommen1.9.0
Apache-2.0
pypidockerpypi:docker
1 Vorkommen7.1.0
Apache-2.0
pypievaluatepypi:evaluate
1 Vorkommen0.4.4
Apache-2.0
pypiexceptiongrouppypi:exceptiongroup
1 Vorkommen1.3.0
MIT
pypiexecutingpypi:executing
1 Vorkommen2.2.0
MIT
pypifastapipypi:fastapi
1 Vorkommen0.115.14
MIT
pypifrozenlistpypi:frozenlist
1 Vorkommen1.7.0
Apache-2.0
pypifsspecpypi:fsspec
1 Vorkommen2025.3.0
BSD-3-Clause · non-standard
pypigitdbpypi:gitdb
1 Vorkommen4.0.12
non-standard
pypigoogle-authpypi:google-auth
1 Vorkommen2.40.3
Apache-2.0
pypigraphenepypi:graphene
1 Vorkommen3.4.3
MIT
pypigraphql-corepypi:graphql-core
1 Vorkommen3.2.6
MIT
pypigraphql-relaypypi:graphql-relay
1 Vorkommen3.2.0
MIT
pypigreenletpypi:greenlet
1 Vorkommen3.2.3
MIT · MIT AND PSF-2.0 · MIT AND Python-2.0
pypigunicornpypi:gunicorn
1 Vorkommen23.0.0
MIT
pypihf-xetpypi:hf-xet
1 Vorkommen1.1.5
Apache-2.0
pypihttpcorepypi:httpcore
1 Vorkommen1.0.9
BSD-3-Clause
pypihttpxpypi:httpx
1 Vorkommen0.28.1
BSD-3-Clause
pypihuggingface-hubpypi:huggingface-hub
1 Vorkommen0.33.2
Apache-2.0 · non-standard
pypiimportlib-metadatapypi:importlib-metadata
1 Vorkommen8.7.0
Apache-2.0 · non-standard
pypiipykernelpypi:ipykernel
1 Vorkommen6.29.5
BSD-3-Clause · non-standard
pypiipythonpypi:ipython
2 Vorkommen8.37.0 · 9.3.0
BSD-3-Clause
pypiipython-pygments-lexerspypi:ipython-pygments-lexers
1 Vorkommen1.1.1
non-standard
pypiitsdangerouspypi:itsdangerous
1 Vorkommen2.2.0
BSD-3-Clause · non-standard
pypijedipypi:jedi
1 Vorkommen0.19.2
MIT
pypijiterpypi:jiter
1 Vorkommen0.10.0
MIT
pypijoblibpypi:joblib
1 Vorkommen1.5.1
BSD-3-Clause
pypijsonschemapypi:jsonschema
1 Vorkommen4.24.0
MIT
pypijsonschema-specificationspypi:jsonschema-specifications
1 Vorkommen2025.4.1
MIT
pypijupyter-clientpypi:jupyter-client
1 Vorkommen8.6.3
non-standard
pypikiwisolverpypi:kiwisolver
1 Vorkommen1.4.8
non-standard
pypimagicattrpypi:magicattr
1 Vorkommen0.1.6
MIT
pypimarkdown-it-pypypi:markdown-it-py
1 Vorkommen3.0.0
MIT
pypimarkupsafepypi:markupsafe
1 Vorkommen3.0.2
BSD-3-Clause · non-standard
pypimatplotlibpypi:matplotlib
1 Vorkommen3.10.3
non-standard
pypimatplotlib-inlinepypi:matplotlib-inline
1 Vorkommen0.1.7
BSD-3-Clause · non-standard
pypimdurlpypi:mdurl
1 Vorkommen0.1.2
MIT
pypimlflow-skinnypypi:mlflow-skinny
1 Vorkommen3.1.1
non-standard
pypimpmathpypi:mpmath
1 Vorkommen1.3.0
non-standard
pypimultidictpypi:multidict
1 Vorkommen6.6.3
Apache-2.0
pypimultiprocesspypi:multiprocess
1 Vorkommen0.70.16
BSD-3-Clause
pypinest-asynciopypi:nest-asyncio
1 Vorkommen1.6.0
non-standard
pypinetworkxpypi:networkx
2 Vorkommen3.4.2 · 3.5
BSD-3-Clause · non-standard
pypinumpypypi:numpy
2 Vorkommen2.2.6 · 2.3.1
0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib · non-standard
pypinvidia-cublas-cu12pypi:nvidia-cublas-cu12
1 Vorkommen12.6.4.1
non-standard
pypinvidia-cuda-cupti-cu12pypi:nvidia-cuda-cupti-cu12
1 Vorkommen12.6.80
non-standard
pypinvidia-cuda-nvrtc-cu12pypi:nvidia-cuda-nvrtc-cu12
1 Vorkommen12.6.77
non-standard
pypinvidia-cuda-runtime-cu12pypi:nvidia-cuda-runtime-cu12
1 Vorkommen12.6.77
non-standard

Diese Seite zeigt 120 von 189 geordneten Zeilen. Die maschinenlesbare Dossier-Datei bewahrt die vollständige exakte Projektion.

OSV

Zugehörige OSV-Meldungen

GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

1 Repository10. Sept. 2026
GHSA-27jp-wm6q-gp25

sqlparse: formatting list of tuples leads to denial of service

2 Repositories10. Sept. 2026
GHSA-284h-m62q-gf8w

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

6 Repositories08. Sept. 2026
GHSA-29pf-2h5f-8g72

HuggingFace transformers vulnerable to remote code execution

11 Repositories10. Sept. 2026
GHSA-29vq-49wr-vm6x

Werkzeug safe_join() allows Windows special device names

6 Repositories10. Sept. 2026
GHSA-2c2j-9gv5-cj73

Starlette has possible denial-of-service vector when parsing large files in multipart forms

4 Repositories10. Sept. 2026
GHSA-2cm6-r77w-6g96

MLflow: trace API endpoints lack proper authorization validators

3 Repositories19. Aug. 2026
GHSA-2cp2-2r3c-7p7r

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

6 Repositories10. Sept. 2026
GHSA-2f96-g7mh-g2hx

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

6 Repositories23. Sept. 2026
GHSA-2fqr-mr3j-6wp8

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

11 Repositories10. Sept. 2026
GHSA-2g68-c3qc-8985

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

1 Repository10. Sept. 2026
GHSA-2h4p-vjrc-8xpq

Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup

5 Repositories10. Sept. 2026
GHSA-2vrm-gr82-f7m5

AIOHTTP has CRLF injection through multipart part content type header construction

10 Repositories10. Sept. 2026
GHSA-2xpw-w6gg-jr37

urllib3 streaming API improperly handles highly compressed data

16 Repositories25. Sept. 2026
→
GHSA-33p9-3p43-82vq

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

2 Repositories10. Sept. 2026
GHSA-3496-9g83-7v6x

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

3 Repositories10. Sept. 2026
GHSA-3749-ghw9-m3mg

PyTorch susceptible to local Denial of Service

3 Repositories10. Sept. 2026
GHSA-37mw-44qp-f5jm

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

3 Repositories10. Sept. 2026
GHSA-38jv-5279-wg99

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

16 Repositories10. Sept. 2026
→
GHSA-3f7w-8rr8-f37f

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

6 Repositories10. Sept. 2026
GHSA-3gq4-3j92-5w49

NLTK: Corpus Reader Sandbox Bypass

5 Repositories08. Sept. 2026
GHSA-3gqm-fcw5-w839

NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure

4 Repositories02. Sept. 2026
GHSA-3hhw-38pf-pxj6

NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

1 Repository08. Sept. 2026
GHSA-3j69-69wj-xqx2

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

5 Repositories10. Sept. 2026
GHSA-3rp5-jjmw-4wv2

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

6 Repositories17. Sept. 2026
GHSA-3wq7-rqq7-wx6j

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

10 Repositories10. Sept. 2026
GHSA-3wxw-xv34-2frg

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

6 Repositories23. Sept. 2026
GHSA-3x9g-8vmp-wqvf

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

9 Repositories10. Sept. 2026
GHSA-42h5-h8qh-vv9v

MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem

3 Repositories13. Juli 2026
GHSA-45hq-cxwh-f6vc

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

17 Repositories10. Sept. 2026
→
GHSA-469j-vmhf-r6v7

NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

4 Repositories10. Sept. 2026
GHSA-46r5-x6jq-v8g6

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

3 Repositories10. Sept. 2026
GHSA-48p4-8xcf-vxj5

urllib3 does not control redirects in browsers and Node.js

8 Repositories10. Sept. 2026
GHSA-4fvr-rgm6-gqmc

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

11 Repositories10. Sept. 2026
GHSA-4g5m-c9r5-49xf

LiteLLM: Local file read via request-supplied OIDC file references

4 Repositories10. Sept. 2026
GHSA-4gmw-gg2m-w46p

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

6 Repositories10. Sept. 2026
GHSA-4jcj-7x88-m979

LiteLLM: MCP Proxy Has Improper Authentication

4 Repositories11. Sept. 2026
GHSA-4m7w-qmgq-4wj5

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

11 Repositories10. Sept. 2026
GHSA-4w7r-h757-3r74

Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer

4 Repositories10. Sept. 2026
GHSA-4x4j-2g7c-83w6

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

17 Repositories10. Sept. 2026
→
GHSA-4x5p-f36r-mxxr

mlflow Creates of Temporary File in Directory with Insecure Permissions

1 Repository10. Sept. 2026
GHSA-4xh5-x5gv-qwph

pip's fallback tar extraction doesn't check symbolic links point to extraction directory

3 Repositories10. Sept. 2026
GHSA-4xpc-pv4p-pm3w

LiteLLM: Authentication Bypass via Host Header Injection

4 Repositories10. Sept. 2026
GHSA-5239-wwwm-4pmq

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

15 Repositories10. Sept. 2026
GHSA-539m-9xh6-q6rr

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

6 Repositories10. Sept. 2026
GHSA-53mr-6c8q-9789

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

4 Repositories10. Sept. 2026
GHSA-53q9-r3pm-6pq6

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

1 Repository07. Aug. 2026
GHSA-54jq-c3m8-4m76

AIOHTTP vulnerable to brute-force leak of internal static file path components

8 Repositories10. Sept. 2026
Interpretationsgrenze

Exakte Identitäten hinein, klare Grenzen hinaus

Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.

Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.

i6eal (2026): GSA Extraction – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 30. Sept. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-5530/

So liest du dieses Dossier

Belegt dieses Repository-Dossier einen Betrieb?
Nein. Es dokumentiert veröffentlichte Abhängigkeiten an einem beobachteten Commit – keine eingesetzte Umgebung.
Warum sind exakte Versionen erforderlich?
OSV- und Registermetadaten lassen sich nur mit einem beobachteten paket@version-Tupel reproduzierbar verknüpfen. Der Collector ersetzt einen Versionsbereich nie durch das neueste Release.
Bedeutet eine fehlende Zeile, dass die Abhängigkeit nicht existiert?
Nein. Sie bedeutet nur „in den begrenzten Dateien und am Repository-Prüfpunkt nicht beobachtet“. Unvollständige Bäume und Parserfehler bleiben ausdrücklich sichtbar.

Du brauchst einen dauerhaften Abhängigkeitsevidenzpfad für eine andere öffentliche Code-Kohorte?

Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.

Datenprojekt besprechenAlle Tools ansehen