T08 · Insecure Dependencies
- Location
SKILL.md:48- Finding
Unpinned npm Dependency Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:48references/overview.md:140-150references/overview.md:401-404references/sdk-guide.md:3-6
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:48:markdown **Install:** `npm install @covalenthq/client-sdk`references/overview.md:140-150:markdown The recommended approach is to use the official [TypeScript Client SDK](https://www.npmjs.com/package/@covalenthq/client-sdk) which supports the Streaming API and manages all WebSocket connections. ```bash npm npm install @covalenthq/client-sdkbash yarn add @covalenthq/client-sdktext `references/overview.md:401-404`: ```markdown The recommended approach is to use the official [GoldRush TypeScript Client SDK](https://www.npmjs.com/package/@covalenthq/client-sdk) which handles authentication automatically and provides a simplified interface for managing stream subscriptions. ```bash npm install @covalenthq/client-sdktext `references/sdk-guide.md:3-6`: ```markdown With the official [TypeScript Client SDK](https://www.npmjs.com/package/@covalenthq/client-sdk), developers can access the Streaming API and leverage the following advanced features described in this guide. ```bash npm install @covalenthq/client-sdktext ### Technical Analysis The documented installation commands do not specify an exact dependency version or integrity constraint. Consequently, users following the instructions receive whichever package release currently satisfies npm's default resolution behavior rather than the release reviewed when this Skill was audited. npm packages can define lifecycle scripts that execute during installation. The installed library will also execute with application privileges when imported at runtime. If the publisher account, registry distribution path, pac ...[truncated 1798 chars]- Remediation
View remediation
Remediation Suggestions
-
Replace floating installation commands with a reviewed exact version, for example:
bash npm install --save-exact @covalenthq/client-sdk@X.Y.ZThe placeholder must be replaced with a specific version that has undergone review.
-
Commit
package-lock.jsonor the corresponding package-manager lockfile and use deterministic installation in CI:bash npm ci -
Review the selected package version, its transitive dependencies, provenance information, published integrity hashes, and lifecycle scripts before approving it.
-
Where package lifecycle scripts are unnecessary, consider installing with:
bash npm ci --ignore-scriptsConfirm first that this does not prevent legitimate package setup.
-
Configure automated dependency scanning and update review so version changes are introduced through explicit, auditable pull requests rather than silently resolved during installation.
-
Run dependency installation and builds in an isolated, least-privileged environment without production credentials. Expose only the secrets required for the specific build stage.
-
Apply the same exact-version guidance consistently in
SKILL.md,references/overview.md, andreferences/sdk-guide.md.
-
