T08 · Insecure Dependencies
- Location
README.en.md:45- Finding
Unpinned Globally Installed SkillHub CLI Creates a Supply-Chain Execution Risk
- Content
View full analysis
- Remediation
View remediation
``` 2. Prefer a project-local dependency over a global installation and commit the generated lockfile: ```bash npm ci npx --no-install skillhub ... ``` 3. Record and verify package integrity through `package-lock.json` or an equivalent lockfile. 4. Review the pinned package and its transitive dependencies before upgrading. 5. Disable unnecessary npm lifecycle scripts where compatible with the package: ```bash npm ci --ignore-scripts ``` 6. Do not run npm installation with administrator or root privileges. 7. Invoke the expected project-local binary rather than relying on whichever `skillhub` executable appears first in `PATH`. 8. Document a controlled upgrade process that includes dependency review, integrity validation, and regression testing before changing the pinned version. ]]>
