T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Alibaba Cloud SDK Dependency
- Content
View full analysis
- Remediation
View remediation
" ``` 2. Generate a locked requirements file containing cryptographic hashes and install with hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Commit the lock file to the Skill package and update it only through a documented dependency-review process. 4. Verify that the package is obtained from the expected official Python package index or a controlled internal mirror. 5. Use automated dependency scanning and review release changes before updating the pinned version. 6. Run the scripts with a dedicated, least-privileged account and narrowly scoped Alibaba Cloud credentials to reduce the impact of dependency compromise. ]]>
