T08 · Insecure Dependencies
- Location
SKILL.md:135- Finding
Mutable Container Image Tag Allows Unreviewed Dependency Replacement
- Content
View full analysis
- Remediation
View remediation
@sha256: ``` - Verify the digest against the publisher's trusted release information before deployment. - Where supported, verify container signatures and provenance using a mechanism such as Sigstore Cosign. - Establish an explicit upgrade process that reviews release notes, retrieves the new digest, tests the image, and updates the Skill only after approval. - Configure deployment tooling so routine redeployments do not silently pull an unreviewed image. - Run the container as a non-root user with minimal Linux capabilities, read-only filesystems where feasible, and only the required volume mounts to limit the impact of a compromised dependency. ]]>
