T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned and Unverified Third-Party Python Dependencies
- Content
View full analysis
=1.8.0 pandas>=1.5.0 ``` `metadata.json:18-23`: ```json "dependencies": { "python": ">=3.8", "packages": [ "jqdatasdk>=1.8.0", "pandas>=1.5.0" ] } ``` `README.md:16-20`: ```markdown ## 📥 安装 ```bash pip install jqdatasdk ``` ``` `SKILL.md:15-19`: ```markdown ## 安装 (Local Data SDK) ```bash pip install jqdatasdk ``` ``` `demo_project/README.md:7-10`: ```markdown 1. 确保已经安装依赖: ```bash pip install -r ../requirements.txt ``` ``` `demo_project/demo.py:3-4`: ```python try: from jqdatasdk import auth, get_price ``` ### Technical Analysis The project specifies `jqdatasdk` and `pandas` using open-ended minimum-version constraints. It does not provide exact version pins, package hashes, or a lock file. The direct `pip install jqdatasdk` instructions are even less restrictive and allow the package resolver to select the latest compatible release available at installation time. Consequently, installations are not reproducible, and the code ultimately imported by the demonstration can differ from the code reviewed during this audit. If a dependency publisher account, package repository, release process, or transitive dependency is compromised, a later package version could introduce malicious behavior without requiring changes to this project. The package names are consistent with the declared JoinQuant functionality, and the audited repository contains no evidence that either dependency is currently malicious. The vulnerability is the absence of controls that prevent an unreviewed future release from being installed and importe ...[truncated 1828 chars]- Remediation
View remediation
