T08 · Insecure Dependencies
- Location
README.md:7- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
openpyxl== ``` 2. Generate and commit a fully resolved lock file that includes transitive dependencies. 3. Use hash verification, such as pip's `--require-hashes`, with reviewed distribution hashes. 4. Install only from the official Python Package Index or a controlled internal mirror: ```bash python -m pip install --index-url https://pypi.org/simple --require-hashes -r requirements.txt ``` 5. Regularly scan locked dependencies for published vulnerabilities and update them through a reviewed process. 6. Replace both unpinned installation instructions with the locked, hash-verified installation command. 7. Avoid installing dependencies with administrative or root privileges. ]]>
