T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned Third-Party Dependencies Permit Unreviewed Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
requirements.txt:1-3; installation instructions also appear inSKILL.md:16-20anddemo_project/README.md:7-10
Vulnerability Type: Supply-chain risk caused by unpinned dependencies and missing integrity verification
Risk Level: MediumVulnerable Code
requirements.txt:1-3:text rqalpha>=5.0.0 pandas>=1.5.0 numpy>=1.20.0SKILL.md:16-20:bash pip install rqalpha rqalpha download-bundledemo_project/README.md:7-10:bash pip install -r ../requirements.txtTechnical Analysis
All declared Python packages use open-ended minimum-version constraints. The primary installation instructions are even less restrictive because
pip install rqalpharequests the latest compatible release. The project does not provide a lockfile, exact version pins, package hashes, or an explicitly trusted package index.Consequently, installations performed at different times can resolve to package versions that were never reviewed with this Skill. Python package installation can run package-controlled build logic, while imported dependencies execute with the privileges of the Python process. A compromised upstream release, compromised dependency account, malicious package served through a configured package mirror, or unsafe future transitive dependency could therefore introduce code that is absent from the audited project.
The
rqalpha download-bundlecommand also performs declared external data retrieval, but the reviewed files do not show that it retrieves or executes code. The confirmed issue is limited to dependency installation without reproducible version and integrity controls.Attack Path
- A user follows the documented command
pip install rqalphaor installsrequirements.txt. - The package resolver queries the configured Python package index or mirror.
- Because the dependencies are not pinned, the resolver may sele ...[truncated 1132 chars]
- A user follows the documented command
- Remediation
View remediation
Remediation Suggestions
-
Replace minimum-version constraints with exact, reviewed versions, for example:
text rqalpha==REVIEWED_VERSION pandas==REVIEWED_VERSION numpy==REVIEWED_VERSION -
Generate and commit a lockfile containing the complete transitive dependency graph.
-
Require package hashes during installation, such as a hash-locked requirements file used with
pip install --require-hashes. -
Configure an explicitly trusted package index instead of relying on arbitrary local
pipconfiguration or untrusted mirrors. -
Install dependencies inside an isolated, non-privileged virtual environment or container. Do not use administrative installation unless strictly necessary.
-
Scan locked direct and transitive dependencies for known vulnerabilities before release and in CI.
-
Update the installation documentation to use the locked dependency file rather than
pip install rqalpha. -
Review and deliberately regenerate pins and hashes whenever dependencies are upgraded.
-
