Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
tree-sitter>=0.23.0 tree-sitter-c>=0.23.0 pycparser>=2.22
- Confidence
- 89% confidence
- Finding
- The dependency is specified with a lower-bound version only, which allows installation of newer, unreviewed releases. This creates supply-chain risk because a future compromised or breaking upstream version could be pulled into the environment without explicit approval or reproducibility guarantees.
