T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Remote Dependencies in Installation Commands
- Content
View full analysis
- Remediation
View remediation
install camino-hotel-finder ``` 2. Pin GitHub installations to a specific reviewed commit hash or signed release tag rather than the repository's mutable default branch. 3. Use package integrity hashes, lockfiles, or registry provenance verification where supported. 4. Install only `camino-hotel-finder` by default instead of all skills in the repository. 5. Document the expected package version and repository commit so users can verify what will be installed. 6. Prefer signed releases and verify signatures or checksums before executing downloaded installation tooling. 7. Periodically review and deliberately update pinned versions rather than resolving new upstream code automatically. ]]>
