Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
reportlab>=3.6.0 PyYAML>=5.4.0 python-docx>=0.8.11 beautifulsoup4>=4.9.0
- Confidence
- 95% confidence
- Finding
- The dependency is specified with a lower-bound only, which allows installation of any newer version and makes builds non-reproducible. This increases supply-chain risk and can unintentionally pull in vulnerable or breaking releases over time, though the line itself is not an exploit mechanism.
