T08 · Insecure Dependencies
- Location
references/convert_pdf.py:4- Finding
Unpinned Playwright Dependency Creates Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
``` 2. Generate and verify hashes for all resolved packages, then install with: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Commit the lock or requirements file to the repository and update both `README.md` and `SKILL.md` to reference it instead of installing an unconstrained package. 4. Use a trusted, explicitly configured package index and prevent unreviewed fallback indexes or mirrors. 5. Run dependency vulnerability and provenance checks during updates. Review dependency changes before regenerating the lock file. 6. Install and run the converter in a dedicated virtual environment under a non-administrative account. ]]>
