Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
numpy scipy
- Confidence
- 94% confidence
- Finding
- The dependency is unpinned, so installs may resolve to different versions over time, including newly introduced vulnerable or incompatible releases. In a security-sensitive or reproducible workflow, this creates supply-chain risk and makes builds non-deterministic.
