T08 · Insecure Dependencies
- Location
SKILL.md:38- Finding
Unpinned npm Dependency Creates a Supply-Chain Execution Risk
- Content
View full analysis
- Remediation
View remediation
``` 2. Commit a reviewed `package-lock.json` and use deterministic installation: ```bash npm ci ``` 3. Where package functionality permits, prevent lifecycle scripts during installation: ```bash npm ci --ignore-scripts ``` If lifecycle scripts are required, inspect them before installation and document why they are necessary. 4. Verify package provenance and lockfile integrity before use. Review the resolved package name, version, registry source, integrity hashes, maintainers, and transitive dependency changes. 5. Run installation and API operations in a restricted environment with access only to the required project directory and Framer credentials. 6. Do not expose unrelated secrets to the Node.js process. Supply only `FRAMER_PROJECT_URL` and `FRAMER_API_KEY` for the specific operation. 7. Use a project-scoped Framer API key with the narrowest available permissions, rotate it if dependency compromise is suspected, and avoid printing it to logs or conversation output. 8. Update both installation instructions so onboarding cannot silently replace the reviewed dependency version with a newer unreviewed release. ]]>
