T08 · Insecure Dependencies
- Location
README_EN.md:85- Finding
Unpinned Third-Party Package Execution During Installation
- Content
View full analysis
- Remediation
View remediation
add ChenChen913/dining-skill ``` 2. Document the expected package version, source, and integrity information so users can verify the downloaded artifact before execution. 3. Prefer an installation method that checks out a specific immutable commit or signed release rather than the repository's moving default branch: ```bash git clone https://github.com/ChenChen913/dining-skill.git cd dining-skill git checkout ``` 4. Where supported, use package-manager lockfiles, registry integrity hashes, provenance attestations, and signature verification. 5. Review the installer package and its transitive dependencies before designating the command as the recommended installation method. 6. Advise users not to run the installation command with `sudo`, as an administrator, or from an account with unnecessary privileges. 7. Apply the same corrected instructions to both `README.md` and `README_EN.md` to keep the documented installation paths consistent. ]]>
