T08 · Insecure Dependencies
- Location
config.example.json:11- Finding
Scheduled execution of an unpinned third-party npm package
- Content
View full analysis
- Remediation
View remediation
``` 3. Commit a lockfile containing dependency versions and integrity hashes, and install with a deterministic command such as: ```bash npm ci ``` 4. Ensure scheduled jobs execute the pinned local binary, for example through `node_modules/.bin/ccusage`, rather than invoking `npx`. 5. Remove `-y` from any remaining interactive `npx` workflows so unexpected package installation requires explicit approval. 6. Run the scheduled process under a dedicated, unprivileged account with access only to the usage data and output files it needs. 7. Add dependency review and update controls so version changes are tested and audited before deployment. ]]>
