T08 · Insecure Dependencies
- Location
SKILL.md:89- Finding
Mutable npm CLI Dependencies Are Downloaded and Executed Through npx
- Content
View full analysis
- Remediation
View remediation
project-name --typescript --tailwind --app npx shadcn@ init npx shadcn@ add button ``` 2. Keep approved versions in a centrally maintained manifest and update them only through a documented dependency-review process. 3. Prefer installing approved CLI versions as development dependencies and executing the local binaries so that versions and integrity metadata are captured by the project lockfile: ```bash npm install --save-dev --save-exact create-next-app@ npm exec create-next-app -- project-name --typescript --tailwind --app ``` 4. Commit and enforce the package lockfile. In CI, use reproducible installation commands such as `npm ci` rather than unconstrained package resolution. 5. Configure npm to use an approved registry or internal artifact mirror. Restrict unexpected registry overrides in project and user `.npmrc` files. 6. Verify package provenance, publisher identity, and integrity before approving a new version. Use dependency scanning and registry audit controls as part of the update process. 7. Run scaffolding tools in an isolated, minimally privileged environment without production credentials, deployment tokens, SSH agents, or unrelated sensitive files. 8. Apply the same correction consistently in: - `SKILL.md` - `UI_UX_MASTER_GUIDE.md` - `references/DESIGN_SYSTEM.md` 9. Add an explicit warning that downloaded CLI tools execute code with the current user's privileges and that users must not substitute unreviewed versions. ]]>
