T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
install survival-basics" ``` 2. Use a lockfile and verify package integrity through the package manager's supported integrity metadata. 3. Configure and document the expected trusted registry rather than relying on ambient registry configuration. 4. Review the pinned package and its transitive dependencies before publication. 5. Prefer a locally installed, verified installer over automatically downloading and executing the latest remotely resolved package. 6. Run installation with the least-privileged account possible and without unnecessary secrets in the environment. 7. Establish an update process in which new package versions are audited before the pinned version is changed. ]]>
