T08 · Insecure Dependencies
- Location
references/api-ref.md:663- Finding
Unpinned Third-Party SDK Installation
- Content
View full analysis
Vulnerability Details
File Location:
references/api-ref.md:663andreferences/api-ref.md:684
Vulnerability Type: Unpinned third-party dependencies without integrity verification
Risk Level: MediumVulnerable Code Snippets:
markdown ### Python (pip install linkdapi) ```python from linkdapi import LinkdAPI, AsyncLinkdAPItext ```markdown ### Node.js (npm install linkdapi) — requires Node 18+ ```js import { LinkdAPI } from 'linkdapi';text ### Technical Analysis The documentation recommends installing the `linkdapi` Python and Node.js packages by mutable registry name. It does not pin reviewed package versions or require lockfiles, hashes, signatures, provenance verification, or another integrity control. Consequently, the code installed by users may differ from the dependency version that was originally intended or reviewed. A compromised publisher account, package registry, or future package release could introduce malicious installation hooks or runtime behavior. In the npm ecosystem, package lifecycle scripts may execute during installation; Python packages can also execute build-related code under applicable installation workflows. The project itself does not contain a malicious payload, and no evidence establishes that the named packages are currently malicious. This finding concerns the supply-chain exposure created by the unsafe installation guidance. ### Attack Path 1. An attacker compromises the relevant package publisher, package registry entry, or a future package release. 2. The attacker publishes a modified version containing malicious installation or runtime behavior. 3. A user or agent follows the documented `pip install linkdapi` or `npm install linkdapi` instruction. 4. Because no reviewed version or artifact digest is specified, the package manager retrieves the attacker-controlled release. 5. Malicious code executes during installation, import, or SDK use with the privileges of the user running the pac ...[truncated 934 chars]- Remediation
View remediation
Remediation Suggestions
- Replace mutable installation instructions with exact, reviewed versions, for example:
pip install linkdapi==<reviewed-version>npm install linkdapi@<reviewed-version> --save-exact
- Publish and maintain lockfiles for executable examples or companion projects.
- For Python, provide a requirements file with cryptographic hashes and recommend
pip install --require-hashes -r requirements.txt. - For Node.js, commit a reviewed lockfile and use
npm cirather than unconstrained installation. - Verify package publisher identity and confirm that registry packages correspond to the documented source repositories.
- Use package provenance, signatures, and artifact attestations where available.
- Disable unnecessary npm lifecycle scripts in sensitive environments, such as with
npm ci --ignore-scripts, after confirming that the SDK does not require them. - Perform dependency vulnerability and malware scanning before release and in CI.
- Document direct HTTPS REST API calls as the lower-dependency alternative.
- Install and run SDKs in a least-privilege, isolated environment with access only to the required API credential and data.
- Replace mutable installation instructions with exact, reviewed versions, for example:
