T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
- Remediation
View remediation
" ``` 2. Maintain a lock file that also constrains transitive dependencies to reviewed versions. 3. Record and enforce cryptographic hashes for every approved distribution artifact. For pip-based installation, use a hashed requirements file together with `pip install --require-hashes`. 4. Prefer reviewed binary wheels from an explicitly configured trusted package index, where practical, and avoid unexpected source builds. 5. Install dependencies inside an isolated virtual environment under a non-privileged account. 6. Use automated dependency scanning and a controlled update process so pinned versions still receive timely security updates. 7. Validate index configuration to prevent untrusted mirrors or additional package sources from taking precedence. ]]>
