T08 · Insecure Dependencies
- Location
SKILL.md:152- Finding
Unpinned Remote Source and Dependencies Are Installed and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:152-159;references/deployment.md:148-170
Vulnerability Type: Supply-chain exposure through mutable remote source and dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:152-159:bash git clone https://github.com/infiniflow/ragflow.git && cd ragflow uv sync --python 3.12 && uv run python3 download_deps.py docker compose -f docker/docker-compose-base.yml up -d # Add to /etc/hosts: 127.0.0.1 es01 infinity mysql minio redis sandbox-executor-manager source .venv/bin/activate && export PYTHONPATH=$(pwd) bash docker/launch_backend_service.sh # Separate terminal: cd web && npm install && npm run devreferences/deployment.md:148-170:bash # 1. Clone and install Python deps git clone https://github.com/infiniflow/ragflow.git cd ragflow/ uv sync --python 3.12 uv run python3 download_deps.py pre-commit install # 2. Start infrastructure services docker compose -f docker/docker-compose-base.yml up -d # 3. Add to /etc/hosts # 127.0.0.1 es01 infinity mysql minio redis sandbox-executor-manager # 4. (If in China) Set HF mirror # export HF_ENDPOINT=https://hf-mirror.com # 5. Launch backend source .venv/bin/activate export PYTHONPATH=$(pwd) bash docker/launch_backend_service.sh # 6. Launch frontend (separate terminal) cd web npm install npm run devTechnical Analysis
The documented default workflow clones the mutable default branch of an external repository and immediately installs or executes its contents. It does not require a reviewed release tag or full commit SHA, verify a signed commit or release artifact, or document hash verification before execution.
The workflow executes several supply-chain-sensitive operations:
uv syncresolves and installs Python dependencies.download_deps.pyruns repository-controlled Python code a ...[truncated 2088 chars]
- Remediation
View remediation
Remediation Suggestions
- Require checkout of a reviewed release tag and preferably a full immutable commit SHA rather than the default branch.
- Verify signed Git tags or commits against trusted maintainer keys before running repository content.
- Publish and verify cryptographic hashes or signatures for downloaded models, archives, binaries, and container images.
- Pin container images by digest rather than relying only on mutable tags.
- Use committed lockfiles and frozen or locked dependency-installation modes for Python and Node.js.
- Disable package lifecycle scripts during initial inspection where practical, and explicitly review any scripts that must run.
- Review
download_deps.py, pre-commit configuration, Compose definitions, and launch scripts before execution. - Perform installation in a disposable, isolated environment using an unprivileged account with minimal filesystem and network access.
- Avoid granting the installation process unrestricted Docker daemon access unless necessary.
- Add automated software composition analysis, artifact provenance verification, and vulnerability scanning to the deployment procedure.
