T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned and Unhashed Third-Party Dependencies
- Content
View full analysis
=2.28.0 pandas>=1.5.0 numpy>=1.21.0 ``` The documented installation command in `README.md`, lines 13-15, consumes these dependency specifications directly: ```bash pip install -r requirements.txt ``` ### Technical Analysis The dependency declarations specify only minimum versions. Consequently, package installation may select any future release satisfying each constraint. No lock file, exact version pin, package hash, or trusted artifact policy is provided. This makes builds non-reproducible and allows dependency code that was not included in this audit to enter the execution environment. Python packages may execute code during installation or when imported. Therefore, compromise of an eligible future release, the configured package index, or the dependency-resolution channel could result in attacker-controlled code being installed. The package names shown are legitimate, and the project does not specify a malicious package repository. This finding represents a supply-chain exposure rather than evidence that the current dependencies or project authors are malicious. ### Attack Path 1. An attacker compromises the publication process or account for a listed dependency, compromises the package-index resolution path, or otherwise causes a malicious future version to be served under a listed package name. 2. The malicious version remains numerically compatible with the lower-bound requirement. 3. A user follows the documented installation procedure and runs: ```bash pip install -r requirements.txt ``` 4. Pip resolves and installs the attacker-controlled release because no exact version or expected artifact hash is enforced. 5. Malicious package code executes during installation or later when the application imports th ...[truncated 939 chars]- Remediation
View remediation
pandas== numpy== ``` 2. Generate a fully resolved lock file that includes transitive dependencies. 3. Record cryptographic hashes for every approved distribution and install with hash enforcement: ```bash pip install --require-hashes -r requirements.txt ``` 4. Permit installation only from explicitly trusted package indexes, preferably through an internally controlled package mirror. 5. Perform dependency updates through a reviewed process that includes vulnerability scanning, compatibility testing, provenance checks, and lock-file regeneration. 6. Install and run the project in an isolated virtual environment or container under a non-privileged account. 7. In CI/CD, reject dependency files containing unpinned packages or missing hashes. ]]>
