T08 · Insecure Dependencies
- Location
scripts/merge_pdf.py:12- Finding
Unpinned Third-Party Dependency Installation Guidance
- Content
View full analysis
- Remediation
View remediation
``` 2. Generate and verify cryptographic hashes for all permitted artifacts. Install with hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Use a lock file generated through a controlled dependency-management process and commit it to the project. 4. Document an approved package index or internal mirror rather than relying on arbitrary user-level pip configuration. 5. Replace the generic installation message with instructions that refer to the project's reviewed dependency file: ```python "install": "python -m pip install --require-hashes -r requirements.txt" ``` 6. Regularly scan pinned dependencies for known vulnerabilities and update them through a reviewed process. 7. Run installation and PDF processing under a non-privileged account with access limited to the required input and output files. ]]>
