T08 · Insecure Dependencies
- Location
scripts/position_calculator.py:14- Finding
Unpinned Third-Party Dependency Installation Guidance
- Content
View full analysis
Vulnerability Details
File Location:
scripts/position_calculator.py, lines 14-19
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: MediumVulnerable Code
python try: import akshare as ak HAS_AKSHARE = True except ImportError: HAS_AKSHARE = False print("⚠️ AKShare 未安装,请运行:pip3 install akshare pandas -U")Technical Analysis
When AKShare is unavailable, the script instructs the user to install or upgrade
akshareandpandasfrom the configured Python package index. The command uses neither exact version constraints nor package hashes:bash pip3 install akshare pandas -UThe
-Uoption requests the latest available releases. Consequently, the installed artifacts and transitive dependency versions may change after the project has been audited. No lockfile, hash-verified requirements file, or trusted index configuration is included to provide reproducible dependency resolution.Python package installation can execute package build logic under the privileges of the user running
pip. Imported package code subsequently runs with the privileges of the Python process. A compromised upstream release, compromised transitive dependency, or unsafe package source could therefore result in arbitrary local code execution.This is supply-chain exposure rather than evidence that the named packages are currently malicious.
Attack Path
- The user runs the script in an environment where
akshareis not installed. - The import fails, and the script displays the unpinned installation command.
- The user executes
pip3 install akshare pandas -U. - The configured package index resolves mutable latest releases and their transitive dependencies.
- If an upstream artifact, dependency, or configured package source has been compromised, malicious build or installation logic executes with the user's privileges.
- Malicious runtime code may also execute when the script later impo ...[truncated 588 chars]
- The user runs the script in an environment where
- Remediation
View remediation
Remediation Suggestions
-
Create a dependency manifest containing reviewed, exact versions of all direct dependencies.
-
Generate and commit a lockfile that also fixes transitive dependency versions.
-
Record package hashes and require hash verification during installation, for example:
bash python3 -m pip install --require-hashes -r requirements.txt -
Remove
-Ufrom user-facing installation guidance so normal execution does not implicitly request unreviewed upgrades. -
Use a dedicated virtual environment and install packages without administrative privileges.
-
Configure an approved package index or an internally controlled artifact mirror.
-
Add automated dependency vulnerability and integrity scanning to the release process.
-
Periodically update dependencies through a controlled review process, regenerate hashes, and test the resulting locked environment before release.
-
