// posture advisories 100 provenance 75 resolution 100 xyz safety 100 load safety 100 supply chain 100 scanner trust 100 code execution 25 fig. 01 — posture on eight axes, 100 is clean. Weakest: code execution at 25. // the finding 0.0 xyz score out of 10 MEDIUM
MEDIUM 1 confirmed finding(s) in the transitive closure; declared dependencies alone rate LOW
MEDIUM trust remote code: further detail on this finding is available to account holders.INFO authored against vulnerable: further detail on this finding is available to account holders.INFO inferred stack advisories: further detail on this finding is available to account holders.3 more findings on this model.
Author jinaai Task feature-extraction Loader transformers License cc-by-nc-4.0 Downloads 129,309 Remote code ships Python that runs on load (trust_remote_code) // dependencies 16 direct, 11 with findings, 116 reachable
Package Evidence Advisories Worst accelerate transitive, transitive 1 MEDIUM transformers direct, runtime 23 none pinned torch direct, install 13 hidden numpy direct, install 8 hidden huggingface-hub direct, install 0 hidden peft direct, install 0 hidden safetensors direct, install 0 hidden tokenizers direct, install 0 hidden
Risk computed 2026-09-22 at 19:51 UTC. Dependencies come from the model's requirements, its declared loader and the code it ships; advisories from NVD, GHSA and OSV.
Model risk is computed from the model's declared and observed Python dependencies and the code it ships. If a finding is wrong, tell us. Report an issue with this page