Skip to content
ai-supply.store
DiscoverCategoriesLeaderboardsCommunityAgent APIFAQ
Sign inSign up free
catalog / DevOps & Infra / DVC
⬡PipelineDevOps & InfraFree

DVC

Git-like version control for ML datasets and pipelines — track experiments, reproduce results, and collaborate on data science projects.

@ai-supply
Installs61k
⟳ upstream 3.67.1 · updated 3mo ago
↗ Source repository
← More DevOps & InfraDevOps & Infra leaderboard →How we grade security →Source ↗
✓ Grade A · 100/100 · SafeSecurity assessment
✓No compromise signals19capabilities surfaced9of 20 OWASP controls clear
Broad capability surfacePotentially unbounded loopExternal endpoints declared · expectedExternal endpoints declared · expected
scanned 16d ago·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓

DVC — Data Version Control

DVC brings Git-style version control to machine learning datasets, models, and pipelines. Define reproducible ML pipelines as code, cache large files in remote storage (S3, GCS, Azure, SSH), and track every experiment with lightweight metafiles committed to Git.

Key features

  • Data versioning — track large files and directories without bloating your Git repo
  • Pipeline DAGs — define stages with dvc.yaml; DVC caches and only re-runs changed stages
  • Experiment tracking — dvc exp run + dvc exp show for a clean experiment table
  • Remote storage — S3, GCS, Azure Blob, SSH, HDFS, and local remotes
  • CI/CD integration — dvc repro in GitHub Actions for reproducible ML pipelines
  • Python API — use programmatically in notebooks or scripts

Quick start

npx ai-supply add dvc-ml-pipeline-versioning

# Or install directly
pip install dvc

# Initialize in a Git repo
git init my-project && cd my-project
dvc init

# Track a dataset
dvc add data/train.csv
git add data/train.csv.dvc .gitignore
git commit -m "Track training data with DVC"

# Define a pipeline stage
dvc run -n train \
  -d data/train.csv -d src/train.py \
  -o model.pkl \
  python src/train.py

# Reproduce the pipeline
dvc repro

Curated mirror of the open-source DVC project (Apache-2.0). Install upstream from the repository.

Rating rank
#1
of 23 in DevOps & Infra
Install rank
#17
of 23 in DevOps & Infra
Security score
100/100 · A
safe
Security rank
#1
of 23 in DevOps & Infra
Installs
61k
cat avg 212k
This listing vs category average
Installs
this
cat avg
Security (of 100)
this
cat avg
Adoption trend
See the DevOps & Infra leaderboard →
✓ Security: Safe · 100100/100 · grade Ascanned 16d ago
✓ no compromise signals19 risk-surface · 6/20 OWASP controls flagged

Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.

What this capability can do · med confidence (static)
⚑ filesystem⚑ shell⚑ network⚑ secrets
egress → dvc.org, test.pypi.org, pypi.org, www.contributor-covenant.org, analytics.dvc.org, git-scm.com, docs.python.org, bugs.python.org +12
58 steps⚑ uses secretsdvc.orgactions/setup-python@v6actions/checkout@v7astral-sh/setup-uv@v7actions/upload-artifact@v7actions/download-artifact@v8pypa/gh-action-pypi-publish@release/v1test.pypi.org

Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).

OWASP Top 10 for LLM Applications
⚠LLM02Sensitive Information Disclosurehigh
Secrets, credentials or PII shipped inside the artifact.
•Embedded credentials — found: credentials in URL · treeverse-dvc-b5dede1/tests/func/test_data_cloud.py (CWE-798)expected
•Embedded credentials — found: private key · treeverse-dvc-b5dede1/tests/remotes/user.key (CWE-798)expected
•Embedded credentials — found: hardcoded credential · treeverse-dvc-b5dede1/tests/unit/remote/test_oss.py (CWE-798)expected
⚠LLM06Excessive Agencyhigh
Over-broad tool/permission surface or unrestricted egress.
•External endpoints declared — 1 distinct host(s) · treeverse-dvc-b5dede1/.git-blame-ignore-revsexpected
•Broad capability surface — 3 high-impact capability categories referenced — verify least-privilege · treeverse-dvc-b5dede1/.github/.test_durations (CWE-272)risk surface
•External endpoints declared — 3 distinct host(s) · treeverse-dvc-b5dede1/.github/.test_durationsexpected
•External endpoints declared — 2 distinct host(s) · treeverse-dvc-b5dede1/.github/PULL_REQUEST_TEMPLATE.mdexpected
•External endpoints declared — 16 distinct host(s) · treeverse-dvc-b5dede1/README.rstexpected
•External endpoints declared — 4 distinct host(s) · treeverse-dvc-b5dede1/dvc/api/data.pyexpected
•External endpoints declared — 5 distinct host(s) · treeverse-dvc-b5dede1/dvc/cli/__init__.pyexpected
•Egress to a private/loopback host — 0.0.0.0 · treeverse-dvc-b5dede1/tests/func/experiments/conftest.py (CWE-918)expected
•Egress to a private/loopback host — 127.0.0.1 · treeverse-dvc-b5dede1/tests/remotes_env.sample (CWE-918)expected
⚠LLM07System Prompt Leakagehigh
Secrets, internal hosts or proprietary logic exposed in shipped prompts.
•Embedded credentials — found: credentials in URL · treeverse-dvc-b5dede1/tests/func/test_data_cloud.py (CWE-798)expected
•Embedded credentials — found: private key · treeverse-dvc-b5dede1/tests/remotes/user.key (CWE-798)expected
•Embedded credentials — found: hardcoded credential · treeverse-dvc-b5dede1/tests/unit/remote/test_oss.py (CWE-798)expected
⚠LLM05Improper Output Handlingmedium
Code that pipes model/user output into shell, eval, SQL or paths unsafely.
•Suspicious code patterns — OS command execution · treeverse-dvc-b5dede1/dvc/daemon.py (CWE-78)expected
•Suspicious code patterns — pickle deserialization · treeverse-dvc-b5dede1/dvc/repo/experiments/executor/base.py (CWE-502)expected
•Suspicious code patterns — unsafe yaml.load · treeverse-dvc-b5dede1/dvc/utils/serialize/_yaml.py (CWE-502)expected
•Suspicious code patterns — dynamic code execution · treeverse-dvc-b5dede1/tests/func/experiments/test_show.py (CWE-95)expected
⚠LLM10Unbounded Consumptionmedium
Unbounded loops/recursion causing DoS or runaway cost.
Enforced at runtime by the gateway (rate limits + spend caps + size caps); static check flags unbounded loops.
•Potentially unbounded loop — an infinite loop (while True / while(1) / for(;;)) may cause runaway consumption · treeverse-dvc-b5dede1/dvc/commands/check_ignore.py (CWE-835)risk surface
§LLM09MisinformationGovernance
Artifacts designed to produce false/deceptive output.
Detectable only by runtime behavioral evaluation; addressed via responsible-use attestation.
✓LLM01Prompt InjectionPassed
✓LLM03Supply ChainPassed
✓LLM04Data and Model PoisoningPassed
Backdoors/poisoning in training data or serialized models.
Behavioral poisoning needs model execution; static check covers unsafe serialization + dataset skew only.
✓LLM08Vector and Embedding WeaknessesPassed
PII or plaintext source leakage in embedding/vector exports.
Embedding inversion/poisoning is largely runtime; static check covers PII in vector exports.
OWASP Machine Learning Security Top 10
⚠ML09Output Integritymedium
Middleware tampering with model outputs in transit.
Gateway enforces TLS + response integrity; static check flags output-rewriting code.
•Suspicious code patterns — OS command execution · treeverse-dvc-b5dede1/dvc/daemon.py (CWE-78)expected
•Suspicious code patterns — pickle deserialization · treeverse-dvc-b5dede1/dvc/repo/experiments/executor/base.py (CWE-502)expected
•Suspicious code patterns — unsafe yaml.load · treeverse-dvc-b5dede1/dvc/utils/serialize/_yaml.py (CWE-502)expected
•Suspicious code patterns — dynamic code execution · treeverse-dvc-b5dede1/tests/func/experiments/test_show.py (CWE-95)expected
§ML01Input Manipulation (Adversarial)Governance
Models vulnerable to adversarial perturbations.
Requires runtime robustness evaluation; addressed via publisher robustness attestation.
§ML03Model InversionGovernance
Training data reconstructable from a model's outputs.
Runtime/evaluation property; addressed via model-card data-provenance + DP attestation.
§ML04Membership InferenceGovernance
Determining whether a record was in the training set.
Runtime/evaluation property; addressed via overfitting disclosure + DP attestation.
§ML08Model SkewingGovernance
Models trained on skewed data producing biased output.
Requires fairness evaluation; addressed via model-card bias/limitations disclosure.
✓ML02Data PoisoningPassed
Poisoned training datasets with triggers or anomalous distributions.
Static check covers trigger phrasing, PII and label skew; full poisoning detection is runtime.
✓ML05Model TheftPassed
Unlicensed re-distribution / license-incompatible derivatives.
Static check verifies license declaration; extraction throttling is runtime.
✓ML06AI Supply ChainPassed
✓ML07Transfer Learning AttackPassed
Backdoored base models / LoRA adapters propagating to derivatives.
Backdoor detection needs behavioral probing; static check covers unsafe serialization + provenance.
✓ML10Model Poisoning (Weights)Passed
Tampered model weight files; integrity must be verifiable.
Static check enforces safe formats + records a content hash for downstream verification.
Other findings (13) · hygiene / uncategorized
•Unrecognized file type — '.gitignore' is not on the allowlist · treeverse-dvc-b5dede1/.dvc/.gitignorerisk surface
•Unrecognized file type — '.dvcignore' is not on the allowlist · treeverse-dvc-b5dede1/.dvcignorerisk surface
•Unrecognized file type — '.git-blame-ignore-revs' is not on the allowlist · treeverse-dvc-b5dede1/.git-blame-ignore-revsrisk surface
•Unrecognized file type — '.gitattributes' is not on the allowlist · treeverse-dvc-b5dede1/.gitattributesrisk surface
•Unrecognized file type — '.test_durations' is not on the allowlist · treeverse-dvc-b5dede1/.github/.test_durationsrisk surface
•Unrecognized file type — '.mailmap' is not on the allowlist · treeverse-dvc-b5dede1/.mailmaprisk surface
•Unrecognized file type — '.cff' is not on the allowlist · treeverse-dvc-b5dede1/CITATION.cffrisk surface
•Unrecognized file type — '.?' is not on the allowlist · treeverse-dvc-b5dede1/LICENSErisk surface
•Suspicious network references — raw IP URL (1 URLs) · treeverse-dvc-b5dede1/tests/func/experiments/conftest.pyexpected
•Suspicious network references — raw IP URL (2 URLs) · treeverse-dvc-b5dede1/tests/integration/test_studio_live_experiments.pyexpected
•Unrecognized file type — '.key' is not on the allowlist · treeverse-dvc-b5dede1/tests/remotes/user.keyrisk surface
•Unrecognized file type — '.pub' is not on the allowlist · treeverse-dvc-b5dede1/tests/remotes/user.key.pubrisk surface
•Unrecognized file type — '.sample' is not on the allowlist · treeverse-dvc-b5dede1/tests/remotes_env.samplerisk surface
✔ verified source · pinned treeverse-dvc-b5dede1
Check against a policy

The same gate an agent runs before installing (POST /api/v1/trust/dvc-ml-pipeline-versioning/check). Click a policy:

Consume DVC programmatically. Authenticate with an API key or session — see Authorize an agent.

# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/dvc-ml-pipeline-versioning

# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/dvc-ml-pipeline-versioning/check \
  -H "Content-Type: application/json" \
  -d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'

# CLI
npx ai-supply add dvc-ml-pipeline-versioning

# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/dvc-ml-pipeline-versioning/install \
  -H "Authorization: Bearer $AIM_KEY"

# MCP tool
install_listing({ "slug": "dvc-ml-pipeline-versioning" })
OpenAPI spec →
vlatest
✓ Security: Safe · 1001mo ago

Curated mirror — latest upstream source. See the repository for tagged releases.

Sign in and install this listing to leave a review.

More from @ai-supply

View profile →
◉Agent
MetaGPT
Multi-agent framework that assigns GPT roles (PM, engineer, QA) to solve complex software tasks end-to-end.
↓ 1.0M
⇄Connector
vLLM
High-throughput, memory-efficient LLM inference engine with PagedAttention and continuous batching.
↓ 892k
⇄Connector
Meilisearch
Lightning-fast open-source search engine with typo-tolerance, semantic hybrid search, and sub-50ms response times.
↓ 811k
△Eval
Weights & Biases (wandb)
ML experiment tracking and visualization — log metrics, hyperparameters, models, and media in real time.
↓ 784k
ai-supply.store

Free, security-vetted AI capabilities — skills, MCPs, plugins, agents, datasets and more, each graded and freshness-tracked, and built for humans and agents alike.

api · v3.1status · all green
Contact
support@ai-supply.storesecurity@ai-supply.store
Catalog
  • Discover
  • Categories
  • Leaderboards
  • Benchmarks
  • Security
  • Scan a repo
Community
  • Community
  • FAQ
For agents
  • Quickstart (60s)
  • Authorize an agent
  • Agent API
  • OpenAPI spec
For builders
  • Publish
  • Dashboard
Account
  • Create account
  • Sign in
  • Settings
Legal
  • Terms
  • Publisher Agreement
  • Acceptable Use
  • Privacy