T08 · Insecure Dependencies
- Location
scripts/requirements.txt:1- Finding
Unpinned and Unhashed Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/requirements.txt:1
Related Installation Instructions:SKILL.md:14-15
Vulnerability Type: Supply-chain risk caused by non-reproducible dependency resolution
Risk Level: MediumVulnerable Code
scripts/requirements.txt:1:text ephem>=4.1.0SKILL.md:14-15:bash python3 -m venv venv && source venv/bin/activate pip install -r scripts/requirements.txtTechnical Analysis
The dependency specification uses only a lower-bound constraint. As a result, installation can resolve to any currently available or future version of
ephemthat satisfies>=4.1.0. The project also provides no package hashes or lock file to verify the integrity and exact identity of the installed artifact.Python package installation may execute package-controlled build or installation logic. Consequently, the effective code installed by following the documented setup procedure can differ from the code reviewed during this audit.
This is a supply-chain hardening weakness rather than evidence that
ephem, the package index, or the project is currently malicious. Exploitation requires compromise of the dependency's publishing channel, a malicious future release, or control of the package index used by the victim.Attack Path
- An attacker compromises the dependency publisher, distribution channel, or package index configured in the victim's environment.
- The attacker publishes a malicious
ephemrelease whose version satisfies>=4.1.0. - A user follows the documented setup instructions.
pipresolves the unconstrained dependency to the malicious release.- Package-controlled build, installation, or runtime code executes with the privileges of the user running
pipor the BaZi application.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the installing or application user. Depending on that user's permissions, this ...[truncated 472 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the lower-bound constraint with an exact version that has been reviewed and tested:
text ephem==<reviewed-version>- Generate a hash-locked dependency file and require hash validation during installation:
bash pip install --require-hashes -r scripts/requirements.txt-
Record hashes for every permitted distribution and platform artifact, or use a lock-generation tool that produces a reproducible requirements file.
-
Install packages only from an explicitly configured, trusted package index. Where appropriate, use an internally controlled package mirror containing approved artifacts.
-
Add automated dependency scanning and controlled update review. Dependency upgrades should be tested and audited before updating the pinned version and hashes.
-
Perform installation and execution as an unprivileged user inside an isolated virtual environment or container. Do not run the documented installation command with administrative privileges.
