T08 · Insecure Dependencies
- Location
references/migration-config.md:6- Finding
Unpinned Package Retrieval and Execution During Migration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a mostly coherent Next.js guidance skill, but its migration guide tells agents/users to run mutable canary/latest package commands that execute external code without pinning or containment guidance.
Review the migration commands before use. Prefer pinned, reviewed versions of Next.js, React, and `@next/codemod`, run codemods in a clean branch or disposable environment, and inspect generated changes before merging. The rest of the skill is ordinary Next.js guidance.
references/migration-config.md:6Unpinned Package Retrieval and Execution During Migration
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# .env.local
DATABASE_URL="postgresql://..."
NEXT_PUBLIC_API_URL="https://api.example.com" # exposed to browser
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
// fetch with cache control
const data = await fetch("https://api.example.com/data", {
next: { revalidate: 60 }, // ISR: revalidate every 60s
// cache: "no-store" // always fresh
// cache: "force-cache" // static, until manual revalidation
The guide recommends running npx @next/codemod@canary upgrade latest, which pulls and executes a canary package version at runtime rather than a stable, pinned release. In a migration guide, this increases supply-chain risk and reduces reproducibility because users may execute changing code with developer privileges.
No suspicious patterns detected.