T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
yt-dlp== ``` 2. Generate a lock file containing hashes for direct and transitive dependencies, and require hash verification: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Install dependencies in a dedicated virtual environment instead of the user's shared package environment: ```bash python3 -m venv .venv . .venv/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` 4. Document the expected package index and disallow untrusted extra indexes. 5. Review dependency updates before changing the lock file. 6. Remove `yt-dlp` from the standard installation command if it remains optional and is not used by the bundled scripts. ]]>
