Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
ainglish>=0.2.42
- Confidence
- 95% confidence
- Finding
- The dependency is specified with a lower-bound version only, which allows installation of any newer release, including unreviewed or compromised versions. This creates a supply-chain risk because builds are not reproducible and a future upstream release could introduce malicious code or breaking security behavior into the skill.
