T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Security-Sensitive Third-Party Dependency
- Content
View full analysis
- Remediation
View remediation
``` Install it with: ```bash pip install --require-hashes -r requirements.txt ``` 3. Pin and hash all transitive dependencies, not only the direct SDK dependency. 4. Restrict installation to an approved package index and prevent fallback to untrusted or user-controlled indexes. 5. Review dependency updates before changing the pinned version. Include vulnerability scanning, provenance verification, and release-diff inspection in the update process. 6. Run the skill under a dedicated, least-privileged account or container. Expose only the required API credential and files to limit the consequences of dependency compromise. 7. Scope and rotate `SIMMER_API_KEY` where supported, and monitor the account for unexpected imports or other API activity. ]]>
