Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
numpy pandas scipy
- Confidence
- 96% confidence
- Finding
- The dependency is unpinned, so installs may resolve to different versions over time, including versions with newly introduced bugs or known vulnerabilities. This creates a supply-chain and reproducibility risk because the environment is not deterministic and security posture can change without code changes.
