T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned and Unaudited Globally Installed CLI Dependency
- Content
View full analysis
- Remediation
View remediation
``` 2. Publish and verify the expected npm integrity hash or signed package provenance. 3. Provide a link to the source revision corresponding exactly to the pinned release. 4. Document a reproducible build and release-verification process. 5. Prefer a project-local installation over a global installation where practical. 6. Disable npm lifecycle scripts during installation if the package does not require them: ```bash npm install --ignore-scripts --save-exact @postnitro/cli@ ``` 7. Regularly audit the pinned package and its transitive dependencies before updating the documented version. 8. Advise users to install the package in an isolated, least-privileged environment. ]]>
