Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
# Corpus Search - Requirements # ChromaDB 向量数据库 chromadb>=0.5.0 # 嵌入模型(语义向量化) sentence-transformers>=2.2.2
- Confidence
- 93% confidence
- Finding
- Using a lower-bound version specifier for chromadb permits installation of any newer release, including versions with breaking changes or newly introduced vulnerabilities. In supply-chain contexts this weakens reproducibility and can expose deployments to compromised or unsafe dependency versions over time.
