T08 · Insecure Dependencies
- Location
README.md:22- Finding
Unpinned Python Dependencies Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Locations:
README.md:22clawhub.json:27pytest_master.py:1374
Vulnerability Type: Uncontrolled third-party dependency resolution
Risk Level: MediumVulnerable Code
README.md:22:bash pip install pytestclawhub.json:27:json "installation": "pip install pytest",pytest_master.py:1374:yaml - run: pip install pytest pytest-covTechnical Analysis
The installation instructions and generated CI example install
pytestandpytest-covwithout exact version constraints or package hashes. Consequently, the packages and their transitive dependencies are resolved from mutable upstream repositories at installation time.This does not demonstrate that any currently referenced package is malicious. However, it prevents reproducible dependency resolution and makes the installation dependent on whichever releases are available when the command runs. If an upstream release or transitive dependency is compromised, the affected package could execute code during installation or later when imported or invoked.
The risk is especially relevant to the CI example because CI runners may have access to repository contents, workflow tokens, environment variables, build artifacts, and other job-scoped credentials.
Attack Path
- An attacker compromises an upstream package release, a transitive dependency, or the package publication process.
- A developer runs the documented
pip install pytestcommand, or a CI workflow adopts the generatedpip install pytest pytest-covexample. - Pip resolves the compromised release because no reviewed version or hash is enforced.
- Malicious package code executes during installation, import, plugin discovery, or test execution.
- The code operates with the permissions of the developer account or CI runner and may access files, environment variables, source code, artifacts, and network ...[truncated 702 chars]
- Remediation
View remediation
Remediation Suggestions
-
Create a reviewed dependency file with exact versions, for example:
text pytest==<reviewed-version> pytest-cov==<reviewed-version> -
Generate and verify hashes for all direct and transitive dependencies, then install with hash enforcement:
bash python -m pip install --require-hashes -r requirements.txt -
Use a lock-generation tool such as
pip-toolsto produce a fully resolved, reproducible dependency set. -
Update
README.md,clawhub.json, and the CI example inpytest_master.pyso they all reference the same locked dependency file rather than installing unconstrained package names. -
Review dependency updates through controlled pull requests and use automated vulnerability scanning before merging them.
-
Run dependency installation and tests in an isolated, least-privileged environment. Avoid exposing unnecessary secrets to dependency installation steps, particularly in CI.
-
For the adjacent GitHub Actions examples, pin third-party actions to reviewed immutable commit SHAs rather than mutable version tags.
-
