T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
install small-engine-repair" ``` 2. Verify the selected release against the package publisher's trusted documentation, provenance, and registry integrity metadata before adoption. 3. Use a lockfile or an equivalent immutable dependency manifest where the installation framework supports one. 4. Prefer a trusted internal registry or package mirror with allowlisting and retention controls for audited artifacts. 5. Enforce package signatures, provenance attestations, or cryptographic checksum verification where supported. 6. Run installation in a sandbox or least-privileged account without production credentials, sensitive environment variables, or unnecessary filesystem access. 7. Review updates explicitly and repeat the security audit before changing the pinned version. 8. Avoid relying on a mutable package tag such as `latest`, including implicitly through an omitted version. ]]>
