T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Noncanonical and Unpinned Python Dependencies Create Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
requirements.txt:1-7; installation instructions atSKILL.md:156-160
Vulnerability Type: Dependency confusion, package-name ambiguity, and unrestricted dependency resolution
Risk Level: MediumVulnerable Code
requirements.txt:1-7:text cv2 dataclasses imagehash matplotlib numpy pdf2image pilSKILL.md:156-160:bash # Python dependencies pip install -r requirements.txtTechnical Analysis
The dependency manifest uses the noncanonical package names
cv2andpil, while the application imports OpenCV and Pillow throughcv2andPIL. The established distribution names for these modules areopencv-pythonandPillow, respectively. Import-module names are not necessarily valid or trustworthy distribution names.The manifest also specifies no versions or integrity hashes. Consequently, installation resolves whichever releases the configured package index currently serves rather than a reproducible, previously reviewed dependency set. This creates supply-chain exposure to package-name confusion, compromised future releases, and unexpected compatibility or security regressions.
The project documentation lists minimum versions for several dependencies, but those constraints are not reflected in the actual
requirements.txtused by the documented installation command. Thedataclassespackage is also generally unnecessary on supported Python versions wheredataclassesis part of the standard library, increasing the dependency surface without a demonstrated need.Attack Path
- A user follows the documented prerequisite command:
pip install -r requirements.txt. pipresolves the ambiguouscv2andpilnames and the unrestricted latest versions of all other dependencies from the configured package index.- An unintended package, maliciously published package, or compromised release is selected.
- Pac ...[truncated 1076 chars]
- A user follows the documented prerequisite command:
- Remediation
View remediation
Remediation Suggestions
- Replace import-module names with the correct distribution names:
- Replace
cv2withopencv-python. - Replace
pilwithPillow.
- Replace
- Remove
dataclassesif the minimum supported Python version provides it in the standard library. - Pin every direct and transitive dependency to a reviewed version through a lock file.
- Add cryptographic hashes and install with
pip --require-hashesto prevent unreviewed artifacts from being substituted. - Generate dependencies from a reviewed source manifest using a tool such as
pip-tools, and update them through a controlled review process. - Audit packages with a dependency scanner and install only from a trusted, explicitly configured package index.
- Keep
SKILL.mdandrequirements.txtsynchronized so the documented versions match the dependencies actually installed.
A corrected source manifest should begin with canonical, constrained package names, for example:
text opencv-python==<reviewed-version> imagehash==<reviewed-version> matplotlib==<reviewed-version> numpy==<reviewed-version> pdf2image==<reviewed-version> Pillow==<reviewed-version>Exact versions and hashes should be selected after compatibility testing and security review rather than copied from an unverified example.
- Replace import-module names with the correct distribution names:
