T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned Third-Party Dependencies Permit Unreviewed Supply-Chain Changes
- Content
View full analysis
Vulnerability Details
File Location:
requirements.txt:1-2
Vulnerability Type: Unpinned third-party dependencies
Risk Level: MediumVulnerable Code
text lunarcalendar shapelyTechnical Analysis
The project declares
lunarcalendarandshapelywithout exact versions or cryptographic hashes. Each installation can therefore resolve to whatever package versions currently satisfy these unconstrained requirements rather than to the versions reviewed during this audit.This does not prove that either package is currently malicious. The vulnerability is that dependency resolution is mutable and lacks integrity enforcement. If an upstream release, maintainer account, package distribution channel, or transitive dependency is compromised, a later installation could retrieve and execute code that was not part of the audited project.
Python packages can execute code during installation or when imported. In this project, both dependencies are imported by runtime scripts, so compromised package code could execute within the privileges and environment of the user running the installation or application.
Attack Path
- An attacker compromises an upstream package release, maintainer account, distribution channel, or relevant transitive dependency.
- The attacker publishes a malicious version under the legitimate package name.
- A user installs the project dependencies using the unpinned
requirements.txt. - The package manager resolves and downloads the malicious or otherwise unreviewed release.
- Malicious code executes during package installation or when the dependency is imported by the project.
- The code gains access to resources available to the installing or runtime user.
Impact Assessment
Successful exploitation could permit arbitrary Python code execution with the privileges of the user installing or running the project. Depending on that environment, the compromised dependency could read or modify accessible fi ...[truncated 358 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin each direct dependency to a specifically reviewed version, for example:
text lunarcalendar==REVIEWED_VERSION shapely==REVIEWED_VERSION -
Generate and commit a lock file or hash-checked requirements file containing resolved transitive dependencies and SHA-256 hashes.
-
Install dependencies with hash enforcement, such as
pip install --require-hashes -r requirements.txt, when using a compatible generated requirements file. -
Obtain packages only from an explicitly configured trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure.
-
Review dependency provenance, release history, known vulnerabilities, and transitive dependency changes before updating pins.
-
Automate dependency vulnerability scanning while keeping updates deliberate and reviewable.
-
Build and install dependencies in a least-privileged, isolated environment without unnecessary credentials or filesystem access.
-
