T08 · Insecure Dependencies
- Location
scripts/run_tests.py:187- Finding
Unpinned Dependencies and Implicit Package Retrieval
- Content
View full analysis
=2.15.0 # For testing (run_tests.py) pytest>=7.2.0 # For better output formatting colorama>=0.4.6 ``` `README.md:332-337`: ```bash pip install -r requirements.txt ``` ```bash npm install --save-dev jest ``` ### Technical Analysis The Python dependencies use open-ended minimum version constraints rather than exact, reviewed versions. No lockfile or package hashes are present in the audited project. Consequently, installation at different times can resolve to different package versions whose code was not included in this audit. The JavaScript test runner invokes `npx jest`. Depending on the npm environment and local package availability, `npx` may resolve or retrieve the Jest package before executing it. This creates a supply-chain execution channel in which package code and installation lifecycle behavior can run with the privileges of the user invoking the script. The subprocess call uses an argument list and does not enable a shell, so the audited code does not expose a direct shell-command injection vulnerability through `self.target`. The risk instead arises from trusting dynamically resolved third-party packages. ### Attack Path 1. An attacker compromises an allowed package release, its publishing account, or the package-resolution infrastructure. 2. A user follows the documented installation instructions, causing the open-ended Python constraints to resolve to the affected release; alternatively, the user invokes ...[truncated 1213 chars]- Remediation
View remediation
