landeshauptstadt-muenchen/mucgptDieses Dossier bewahrt 1.444 exakte Komponentenvorkommen aus 7 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.
Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.
Projekt-ID + Commit-SHA + exakter EvidenzpfadJede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.
sha256:49079619359e8a92c2b62dd98fa5b65108967bd9db6a90a35ad1aa14cd9f562fsha256:26725828dd6a0a9fa5d85a4a7ae1b7369a5c64393e21789c3781850e1e0f1291sha256:3883845d12886f16c8117a166d7a257dc1c64218b5c79cc44c8779e24b4b7adesha256:6ce1d6f1c957bfdf944bad45b1985196f39cd7832b479e1b2b6007fe2cef620asha256:8d46f05c7bd971ad1fe84adfd32638e8c436c0973b7969b31368dd4e364739a5sha256:5e8999cd57c92cb116c8b5178eef208f9e4cd9df89cd7c3d47641deabe078d0dpypi:langchain-core1.5.67 zurückgegebene OSV-Meldungenpypi:langchain-community0.4.14 zurückgegebene OSV-Meldungenpypi:langchain1.3.153 zurückgegebene OSV-Meldungenpypi:langchain-text-splitters1.1.22 zurückgegebene OSV-Meldungenpypi:langgraph1.2.112 zurückgegebene OSV-Meldungenpypi:langchain-openai1.2.11 zurückgegebene OSV-Meldungpypi:anthropic0.122.0pypi:openai2.31.0npm:@huggingface/transformers4.2.0pypi:langchain-mcp-adapters0.2.2pypi:langchain-protocol0.0.18pypi:tiktoken0.12.0pypi:aiohttp3.14.333 zurückgegebene OSV-Meldungennpm:undici6.28.026 zurückgegebene OSV-Meldungennpm:dompurify3.4.1318 zurückgegebene OSV-Meldungenpypi:pyjwt2.13.017 zurückgegebene OSV-Meldungennpm:react-router7.18.213 zurückgegebene OSV-Meldungenpypi:tornado6.5.813 zurückgegebene OSV-Meldungenpypi:cryptography50.0.09 zurückgegebene OSV-Meldungenpypi:python-multipart0.0.31 · 0.0.328 zurückgegebene OSV-Meldungenpypi:starlette1.3.18 zurückgegebene OSV-Meldungennpm:brace-expansion1.1.18 · 2.1.4 · 5.0.97 zurückgegebene OSV-Meldungenpypi:urllib32.7.07 zurückgegebene OSV-Meldungennpm:vite8.1.57 zurückgegebene OSV-Meldungennpm:js-yaml4.3.25 zurückgegebene OSV-Meldungenpypi:pyasn10.6.45 zurückgegebene OSV-Meldungenpypi:jinja23.1.64 zurückgegebene OSV-Meldungennpm:postcss8.5.264 zurückgegebene OSV-Meldungenpypi:soupsieve2.9.14 zurückgegebene OSV-Meldungenpypi:langsmith0.11.03 zurückgegebene OSV-Meldungennpm:markdown-it14.3.03 zurückgegebene OSV-Meldungenpypi:mcp1.28.1 · 1.29.03 zurückgegebene OSV-Meldungennpm:minimatch10.2.6 · 3.1.5 · 5.1.93 zurückgegebene OSV-Meldungennpm:nanoid3.3.183 zurückgegebene OSV-Meldungenpypi:requests2.33.13 zurückgegebene OSV-Meldungenpypi:anyio4.14.22 zurückgegebene OSV-Meldungennpm:browserslist4.28.72 zurückgegebene OSV-Meldungenpypi:filelock3.29.02 zurückgegebene OSV-Meldungennpm:flatted3.4.42 zurückgegebene OSV-Meldungennpm:linkify-it5.0.22 zurückgegebene OSV-Meldungenpypi:mako1.3.122 zurückgegebene OSV-Meldungennpm:picomatch2.3.2 · 4.0.52 zurückgegebene OSV-Meldungenpypi:protobuf6.33.62 zurückgegebene OSV-Meldungennpm:@babel/core7.29.61 zurückgegebene OSV-Meldungnpm:@humanfs/node0.16.81 zurückgegebene OSV-Meldungnpm:ajv6.15.0 · 8.20.01 zurückgegebene OSV-Meldungpypi:certifi2026.4.22 · 2026.7.221 zurückgegebene OSV-Meldungpypi:click8.3.3 · 8.4.21 zurückgegebene OSV-Meldungnpm:fast-uri3.1.71 zurückgegebene OSV-Meldungnpm:glob11.1.01 zurückgegebene OSV-Meldungpypi:h110.16.01 zurückgegebene OSV-Meldungpypi:idna3.15 · 3.181 zurückgegebene OSV-Meldungpypi:jupyter-core5.9.11 zurückgegebene OSV-Meldungpypi:langchain-classic1.0.71 zurückgegebene OSV-Meldungpypi:langgraph-checkpoint4.1.11 zurückgegebene OSV-Meldungpypi:langgraph-sdk0.4.21 zurückgegebene OSV-Meldungpypi:marshmallow3.26.21 zurückgegebene OSV-Meldungnpm:mdast-util-to-hast13.2.11 zurückgegebene OSV-Meldungpypi:orjson3.11.91 zurückgegebene OSV-Meldungnpm:path-to-regexp6.3.01 zurückgegebene OSV-Meldungnpm:prismjs1.30.01 zurückgegebene OSV-Meldungpypi:pydantic-settings2.14.21 zurückgegebene OSV-Meldungpypi:pygments2.20.01 zurückgegebene OSV-Meldungpypi:pytest9.0.31 zurückgegebene OSV-Meldungpypi:python-dotenv1.2.21 zurückgegebene OSV-Meldungnpm:rollup4.62.41 zurückgegebene OSV-Meldungpypi:tqdm4.67.31 zurückgegebene OSV-Meldungnpm:uuid14.0.01 zurückgegebene OSV-Meldungpypi:virtualenv21.2.4 · 21.3.11 zurückgegebene OSV-Meldungnpm:yaml2.9.01 zurückgegebene OSV-Meldungnpm:@antfu/install-pkg1.1.0npm:@apideck/better-ajv-errors0.3.7npm:@atlaskit/pragmatic-drag-and-drop1.8.1npm:@atlaskit/pragmatic-drag-and-drop-hitbox1.2.0npm:@babel/code-frame7.29.7npm:@babel/compat-data7.29.7npm:@babel/generator7.29.8npm:@babel/helper-annotate-as-pure7.29.7npm:@babel/helper-compilation-targets7.29.7npm:@babel/helper-create-class-features-plugin7.29.7npm:@babel/helper-create-regexp-features-plugin7.29.7npm:@babel/helper-define-polyfill-provider0.6.8npm:@babel/helper-globals7.29.7npm:@babel/helper-member-expression-to-functions7.29.7npm:@babel/helper-module-imports7.29.7npm:@babel/helper-module-transforms7.29.7npm:@babel/helper-optimise-call-expression7.29.7npm:@babel/helper-plugin-utils7.29.7npm:@babel/helper-remap-async-to-generator7.29.7npm:@babel/helper-replace-supers7.29.7npm:@babel/helper-skip-transparent-expression-wrappers7.29.7npm:@babel/helper-string-parser7.29.7npm:@babel/helper-validator-identifier7.29.7npm:@babel/helper-validator-option7.29.7npm:@babel/helper-wrap-function7.29.7npm:@babel/helpers7.29.7npm:@babel/parser7.29.8npm:@babel/plugin-bugfix-firefox-class-in-computed-class-key7.29.7npm:@babel/plugin-bugfix-safari-class-field-initializer-scope7.29.7npm:@babel/plugin-bugfix-safari-id-destructuring-collision-in-function-expression7.29.7npm:@babel/plugin-bugfix-safari-rest-destructuring-rhs-array7.29.7npm:@babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining7.29.7npm:@babel/plugin-bugfix-v8-static-class-fields-redefine-readonly7.29.7npm:@babel/plugin-proposal-private-property-in-object7.21.0-placeholder-for-preset-env.2npm:@babel/plugin-syntax-import-assertions7.29.7npm:@babel/plugin-syntax-import-attributes7.29.7npm:@babel/plugin-syntax-unicode-sets-regex7.18.6npm:@babel/plugin-transform-arrow-functions7.29.7npm:@babel/plugin-transform-async-generator-functions7.29.7npm:@babel/plugin-transform-async-to-generator7.29.7npm:@babel/plugin-transform-block-scoped-functions7.29.7npm:@babel/plugin-transform-block-scoping7.29.7npm:@babel/plugin-transform-class-properties7.29.7npm:@babel/plugin-transform-class-static-block7.29.7npm:@babel/plugin-transform-classes7.29.7npm:@babel/plugin-transform-computed-properties7.29.7npm:@babel/plugin-transform-destructuring7.29.7npm:@babel/plugin-transform-dotall-regex7.29.7npm:@babel/plugin-transform-duplicate-keys7.29.7npm:@babel/plugin-transform-duplicate-named-capturing-groups-regex7.29.7Diese Seite zeigt 120 von 1.202 geordneten Zeilen. Die maschinenlesbare Dossier-Datei bewahrt die vollständige exakte Projektion.
LinkifyIt#match scan loop has quadratic algorithmic complexity
10. Sept. 2026minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
10. Sept. 2026Certifi removes GLOBALTRUST root certificate
10. Sept. 2026markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of seconds
29. Sept. 2026flatted vulnerable to unbounded recursion DoS in parse() revive phase
10. Sept. 2026js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
08. Sept. 2026nanoid: non-secure generators can loop indefinitely with negative size
10. Sept. 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
10. Sept. 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
10. Sept. 2026ajv has ReDoS when using `$data` option
10. Sept. 2026LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
10. Sept. 2026undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
29. Sept. 2026PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
30. Sept. 2026Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
10. Sept. 2026React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
10. Sept. 2026undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
29. Sept. 2026Undici has an HTTP Request/Response Smuggling issue
10. Sept. 2026nanoid: custom generators can loop indefinitely when size is zero
10. Sept. 2026AIOHTTP has CRLF injection through multipart part content type header construction
10. Sept. 2026React Router vulnerable to XSS via Open Redirects
03. Feb. 2026Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
10. Sept. 2026urllib3 streaming API improperly handles highly compressed data
25. Sept. 2026React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
10. Sept. 2026Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
10. Sept. 2026undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
10. Sept. 2026LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
10. Sept. 2026path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
10. Sept. 2026markdown-it is has a Regular Expression Denial of Service (ReDoS)
10. Sept. 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10. Sept. 2026DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
10. Sept. 2026brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
10. Sept. 2026minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
10. Sept. 2026Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
10. Sept. 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
10. Sept. 2026undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
29. Sept. 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
10. Sept. 2026undici vulnerable to Denial of Service via unbounded decompression of compressed responses
29. Sept. 2026Marshmallow has DoS in Schema.load(many)
10. Sept. 2026Langchain SQL Injection vulnerability
07. Juli 2026yaml is vulnerable to Stack Overflow via deeply nested YAML collections
10. Sept. 2026urllib3 does not control redirects in browsers and Node.js
10. Sept. 2026Undici has CRLF Injection in undici via `upgrade` option
10. Sept. 2026React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
10. Sept. 2026undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
10. Sept. 2026mdast-util-to-hast has unsanitized class attribute
10. Sept. 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
10. Sept. 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
10. Sept. 2026Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
10. Sept. 2026Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.
Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.i6eal (2026): MUCGPT – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 30. Sept. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-7202/
Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.
Diese Tools passen thematisch dazu.