T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned Third-Party Dependencies Allow Unreviewed Package Code
- Content
View full analysis
=1.3.0 pandas>=1.5.0 ``` `SKILL.md:16-18` ```bash ## 安装 ```bash pip install tushare --upgrade ``` ``` `README.md:18-20` ```bash ## 📥 安装 ```bash pip install tushare --upgrade ``` ``` `demo_project/README.md:6-10` ```bash 1. 确保已经安装依赖: ```bash pip install -r ../requirements.txt ``` ``` ### Technical Analysis The project instructs users to install third-party Python packages using `--upgrade` or lower-bound-only version constraints. Neither exact versions nor package hashes are provided, and no lock file records reviewed transitive dependencies. The constraints therefore permit pip to select future releases that were not available or reviewed when this Skill was published. The `--upgrade` option makes this behavior explicit by requesting a newer eligible release. If an allowed direct or transitive dependency is compromised, a malicious source distribution could execute code through its build backend during installation. A malicious installed package could also execute when imported at runtime. This is a supply-chain and reproducibility weakness. The audit did not find evidence that the currently named packages are malicious; the risk arises from allowing mutable, unverified future package versions. ### Attack Path 1. An attacker compromises the publication account or release process of an allowed direct or transitive dependency. 2. The attacker publishes a malicious version satisfying `tushare>=1.3.0`, `pandas>=1.5.0`, or an unrestricted transitive dependency constraint. 3. A user follows the documented `pip install tushare --upgrade` command or installs `requirements.txt`. 4. Pip resolves and downloads the attacker-controlled release becaus ...[truncated 1093 chars]- Remediation
View remediation
pandas== ``` 2. Generate and commit a lock file that records exact versions of all direct and transitive dependencies. 3. Use package integrity hashes and enforce them during installation: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Remove `--upgrade` from normal installation instructions. Perform upgrades through a controlled dependency-review process instead. 5. Configure a trusted package index explicitly and prevent unintended fallback to untrusted or internal-looking package sources. 6. Review release provenance, signatures, and package metadata before updating locked versions. 7. Run dependency installation and the demo in an isolated virtual environment or container under a non-privileged account. 8. Add automated dependency scanning and scheduled review of pinned versions so security updates can be adopted without accepting arbitrary future releases. ]]>
