T08 · Insecure Dependencies
- Location
scripts/install.sh:14- Finding
Unpinned Dependencies and Untrusted Configurable Package Index
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install.sh, lines 14–20
Vulnerability Type: Supply-chain exposure through unpinned packages and unsafe package-index configuration
Risk Level: Highbash python -m pip install --upgrade pip setuptools wheel >/dev/null if [[ -n "${RAGLITE_PIP_INDEX_URL:-}" ]]; then python -m pip install --upgrade -i "$RAGLITE_PIP_INDEX_URL" --extra-index-url https://pypi.org/simple raglite-chromadb else python -m pip install --upgrade raglite-chromadb fiTechnical Analysis
The installer downloads and installs the latest available versions of
pip,setuptools,wheel, andraglite-chromadbwithout exact version constraints or cryptographic hashes. Consequently, the code executed during installation is not fixed to the version reviewed with this skill and may change whenever the installer runs.The
RAGLITE_PIP_INDEX_URLenvironment variable also permits an arbitrary package repository to become the primary index. Combining a configurable primary index with the public PyPI repository through--extra-index-urlexposes package resolution to dependency-confusion and malicious-index attacks. An attacker who can influence the environment, package index, DNS/network path, or an eligible package release may cause pip to select and install attacker-controlled content.Python packages can execute code during build and installation, and the resulting package is subsequently trusted when
ragliteis invoked. This creates a code-execution path outside the audited project files.Attack Path
- An attacker compromises an eligible package release, publishes a dependency-confusion candidate, or causes
RAGLITE_PIP_INDEX_URLto reference an attacker-controlled package index. - A user runs
scripts/install.sh. - Pip resolves unpinned package versions from the configured index and/or PyPI.
- Pip downloads the attacker-controlled package or dependency.
- Malicious build, installation, or runtime cod ...[truncated 839 chars]
- An attacker compromises an eligible package release, publishes a dependency-confusion candidate, or causes
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed, exact version, including
raglite-chromadb,pip,setuptools, andwheel. - Generate a lock file containing all transitive dependencies and their cryptographic hashes.
- Install with
--require-hashesso modified or unexpected distributions are rejected. - Avoid combining an arbitrary primary index with PyPI through
--extra-index-url. Use a single trusted repository or a controlled mirror containing all approved packages. - If custom indexes are required, validate
RAGLITE_PIP_INDEX_URLagainst an explicit allowlist and require authenticated HTTPS with appropriate certificate verification. - Prefer prebuilt, verified wheels where possible and disable unnecessary source builds to reduce installation-time code execution.
- Perform dependency scanning and package provenance verification before updating the lock file.
- Reproduce installation in an isolated, least-privileged environment before promoting dependency updates.
- Pin every direct dependency to a reviewed, exact version, including
