Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
rich PyYAML
- Confidence
- 95% confidence
- Finding
- The dependency 'rich' is unpinned, so installs may resolve to different versions over time, reducing build reproducibility and increasing supply-chain risk if a bad or incompatible release is published. While this alone is not an immediate exploit, it weakens dependency integrity controls and can expose the skill to unexpected vulnerable versions.
