T08 · Insecure Dependencies
- Location
scripts/fortune_fusion.py:285- Finding
Unpinned Third-Party Dependency Installation Guidance
- Content
View full analysis
Any: try: from iztro_py import astro except ModuleNotFoundError as exc: raise RuntimeError("未安装 iztro-py,请先安装:pip install iztro-py") from exc return astro ``` ```python def render_jpg_cairosvg(svg: str, quality: int = 92) -> bytes: try: import cairosvg except ModuleNotFoundError as exc: raise RuntimeError("生成 JPG 需要 cairosvg,请先安装:pip install cairosvg") from exc try: from PIL import Image except ModuleNotFoundError as exc: raise RuntimeError("生成 JPG 需要 pillow,请先安装:pip install pillow") from exc ``` ```javascript #!/usr/bin/env node import { astro } from 'iztro'; ``` ### Technical Analysis The runtime error messages instruct users to install `iztro-py`, `cairosvg`, and `pillow` without specifying reviewed versions or integrity hashes. The JavaScript engine also imports `iztro`, while the audited project contains no `package.json`, package-manager lockfile, Python dependency manifest, or hash-locked requirements file. Bare installation commands resolve whatever package version the configured registry currently serves. Consequently, the effective dependency code may differ from the code that was tested or reviewed. This creates a conditional supply-chain risk if a dependency release, package registry, mirror, DNS path, or local package-manager configuration is compromised. The project does not automatically install these packages, and no evidence showed that the named packages are intentionally malicious. Exploitation therefore depends on a user or deployment process following the unpinned installation guidance. ### Attack Path 1. A user invokes functionalit ...[truncated 1278 chars]- Remediation
View remediation
