T08 · Insecure Dependencies
Warning
- Location
SKILL.md:5- Finding
Unpinned Remote Dependency Installed Globally from a Mutable Git Repository
- Content
View full analysis
- Remediation
View remediation
``` 2. Prefer a signed, versioned release from a trusted package registry when available. Pin the exact version rather than using a range or moving tag. 3. Verify downloaded artifacts using a published cryptographic checksum or signature before installation. 4. Record the reviewed version, commit hash, expected checksum, and upstream source in `SKILL.md` so installations are reproducible and auditable. 5. Use package-manager provenance or signature verification where supported, and reject installation when verification fails. 6. Avoid elevated privileges. Perform installation under a dedicated, least-privileged user account or inside a sandbox/container when practical. 7. Review dependency installation hooks and the resulting executable before recommending an updated version or commit. ]]>
