T08 · Insecure Dependencies
- Location
SKILL.md:608- Finding
Unpinned Third-Party Dependencies and Source Revision
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:608-626
Vulnerability Type: Supply-chain risk through unpinned packages and source code
Risk Level: MediumVulnerable Code Snippet:
bash # Basic installation (CPU, ONNX backend) pip install openocr-python # GPU-accelerated ONNX inference pip install openocr-python[onnx-gpu] # PyTorch backend (for server mode) pip install openocr-python[pytorch] # Gradio demos pip install openocr-python[gradio] # All optional dependencies pip install openocr-python[all] # From source git clone https://github.com/Topdu/OpenOCR.git cd OpenOCR python build_package.py pip install ./build/dist/openocr_python-*.whlTechnical Analysis
The documented installation commands retrieve
openocr-pythonand its optional dependency trees without version constraints or cryptographic hashes. Consequently, the installed code is determined by the package versions available when the commands are run, rather than by a revision reviewed with this Skill.The source installation alternative similarly clones the repository's current default branch without selecting a reviewed tag or commit. It then executes
python build_package.pyand installs the resulting wheel. These steps execute externally maintained code that can change after this Skill has been audited.This is a supply-chain weakness rather than evidence that the currently referenced OpenOCR project is malicious. Exploitation would require compromise of a package, transitive dependency, distribution account, repository, or upstream release process.
Attack Path
- An attacker compromises an upstream package or one of its transitive dependencies, publishes a malicious release, or gains control over the referenced repository.
- The user follows one of the unpinned installation procedures in
SKILL.md. pipresolves the dependency to the attacker-controlled releas ...[truncated 941 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin
openocr-pythonand every transitive dependency to reviewed versions in a lock file. -
Require artifact integrity verification using hashes, such as a generated requirements file used with
pip install --require-hashes. -
Pin source installations to a reviewed immutable commit hash or signed release tag instead of the default branch:
bash git clone https://github.com/Topdu/OpenOCR.git cd OpenOCR git checkout --detach <reviewed-commit-hash> -
Verify release signatures or published checksums before building or installing artifacts.
-
Perform installation in an isolated virtual environment or container under a non-privileged account.
-
Maintain dependency scanning and periodically review pinned upgrades before adopting them.
-
Document the expected model sources and verify automatically downloaded model files with cryptographic checksums.
-
