Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
requests>=2.28.0
- Confidence
- 95% confidence
- Finding
- The dependency is specified with a lower bound only (`requests>=2.28.0`), which permits installation of different versions over time and weakens reproducibility and supply-chain control. This can unexpectedly pull in vulnerable or behavior-changing releases depending on environment and resolution time, making security review and incident response harder.
