T08 · Insecure Dependencies
- Location
scripts/toolkit-bootstrap.sh:132- Finding
Unpinned Third-Party Python Package Installation
- Content
View full analysis
/dev/null || pip install --quiet "$pkg" 2>/dev/null else pip3 install "$pkg" 2>/dev/null || pip install "$pkg" 2>/dev/null fi } ``` The script also downloads an unpinned Playwright browser artifact: ```bash if check_python_module "playwright" && ! python3 -c "from playwright.sync_api import sync_playwright; p=sync_playwright().start(); p.chromium" 2>/dev/null; then warn "Playwright is installed but the Chromium browser is unavailable" if [[ "$CHECK_ONLY" == false ]]; then info "Downloading Chromium..." playwright install chromium 2>/dev/null || warn "Chromium download failed; run manually: playwright install chromium" fi fi ``` ### Technical Analysis The bootstrap script installs packages by name from the Python package index without specifying reviewed versions, cryptographic hashes, a lockfile, or an explicitly trusted index. The package names originate from the fixed `TOOLS` array, so direct command injection through `pkg` was not identified. However, commands such as `pip3 install "$pkg"` resolve mutable package releases and their transitive dependencies at installation time. Consequently, the code executed or installed by the bootstrap can differ from the code reviewed during this audit. If a referenced package, one of its dependencies, its maintainer account, or the configured package index is compromised, a malicious release can be selected. Python installation mechanisms may execute build backends or other pac ...[truncated 2515 chars]- Remediation
View remediation
