Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
numpy trimesh shapely mapbox_earcut
- Confidence
- 96% confidence
- Finding
- The dependency is specified without a version pin, which makes builds non-reproducible and can cause the skill to install newly released upstream packages with unexpected breaking changes or security regressions. In a supply-chain context, unpinned dependencies increase exposure to malicious or compromised releases because the resolved version can change over time.
