Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
Pillow>=10.0,<13 numpy>=1.24
- Confidence
- 83% confidence
- Finding
- The numpy dependency is only lower-bounded and not fully pinned, which harms build reproducibility and can allow unexpected or later-vulnerable versions to be installed. This is generally a supply-chain hygiene issue rather than an immediate exploit, but it can increase risk over time.
