Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
requests>=2.28.0 python-dateutil>=2.8.0
- Confidence
- 94% confidence
- Finding
- The dependency is specified with only a lower bound, so builds may resolve to different versions over time and can unexpectedly pull in a newly introduced vulnerable or breaking release. In a monitoring and alerting skill that depends on network libraries, non-reproducible installs increase supply-chain risk and make security patch validation harder.
