Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
jieba>=0.42.1 snownlp>=0.12.3 textblob>=0.17.1
- Confidence
- 92% confidence
- Finding
- The dependency is specified with a lower bound only, which allows future major or minor versions to be installed without review. This can introduce supply-chain risk through breaking changes or newly introduced malicious/compromised releases, reducing build reproducibility and making security posture harder to control.
