T08 · Insecure Dependencies
- Location
README.md:25- Finding
Unpinned Third-Party Packages and Mutable Sources Are Executed During Installation
- Content
View full analysis
- Remediation
View remediation
add seedeai/seede-skill@ npm install -g seede-cli@ ``` 2. If repository syntax does not support release versions, pin the skill to a reviewed immutable commit hash rather than a branch or mutable tag. 3. Publish and verify expected integrity hashes or signed release artifacts before installation. 4. Use a lockfile for local or CI installation so transitive dependency versions remain reproducible. Prefer a project-local installation over a global installation where practical. 5. Run package installation in a restricted environment with minimal filesystem access, no unnecessary credentials, and limited network access. 6. Disable npm lifecycle scripts during initial acquisition where supported: ```bash npm install --ignore-scripts seede-cli@ ``` Lifecycle scripts should only be enabled after reviewing whether they are required and inspecting their implementation. 7. Document the expected npm registry and trusted repository source to reduce registry substitution and dependency-confusion risks. 8. Add automated dependency auditing, provenance verification, and periodic review of pinned versions before upgrades. ]]>
