Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
jsonschema>=4.19.0 pyyaml>=6.0 jinja2>=3.1.0
- Confidence
- 89% confidence
- Finding
- The dependency is specified with only a lower bound, which allows builds to resolve to different versions over time and can unexpectedly introduce vulnerable or incompatible releases. In a form engine that processes schemas and renders dynamic content, dependency drift increases supply-chain risk and makes security posture harder to reproduce and audit.
