T08 · Insecure Dependencies
- Location
SKILL.md:56- Finding
Unpinned Global Installation of a Mutable Third-Party Package
- Content
View full analysis
- Remediation
View remediation
``` 2. Document the expected npm registry and package publisher. 3. Record and verify package integrity metadata or a trusted digest where the installation workflow permits it. 4. Prefer a project-local installation over a global installation, then invoke the binary through a controlled package script or `npx --no-install`. 5. Review package lifecycle scripts and release notes before updating the pinned version. 6. Establish an explicit dependency-update process so new releases are reviewed before the documentation is changed. ]]>
