T08 · Insecure Dependencies
- Location
references/install.md:8- Finding
Unpinned Third-Party CLI Installation Enables Supply-Chain Code Execution
- Content
View full analysis
- Remediation
View remediation
" ``` 2. Use a lock file or requirements file containing cryptographic hashes, and install with hash verification: ```sh python3 -m pip install --require-hashes -r requirements.txt ``` 3. Pin all transitive dependencies or use a reproducible dependency-locking process so dependency resolution cannot silently change after review. 4. If source installation must remain available, clone or fetch a reviewed release and check out an immutable commit hash. Verify the release signature or published checksum before installation. 5. Replace the deprecated `python setup.py install` workflow with a modern, reviewed build artifact and installer. Do not execute code directly from a mutable default branch. 6. Pin the Homebrew formula or document a verified release and integrity-checking procedure rather than relying on the current state of a mutable external tap. 7. Recommend installation in a dedicated virtual environment under a non-administrative account. Explicitly warn users not to use `sudo` or administrator privileges unless a separately justified deployment requirement exists. 8. Document the expected publisher, repository, version, checksum, and verification steps so users can validate that the downloaded artifact is authentic before execution. ]]>
