T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Mutable Global npm Dependency Creates a Supply-Chain Execution Risk
- Content
View full analysis
- Remediation
View remediation
``` 2. Prefer a project-local development dependency over global installation. Invoke it through an npm script or a locally resolved executable so its scope is limited to the project. 3. Commit `package.json` and `package-lock.json`, then use deterministic installation in automation: ```bash npm ci ``` 4. Review the selected package version, its lifecycle scripts, and its transitive dependency graph before recommending installation. 5. Verify package provenance and registry metadata. Where operationally supported, enforce registry allowlists, package integrity checks, and npm provenance verification. 6. Consider initially installing with lifecycle scripts disabled: ```bash npm install --ignore-scripts --save-dev --save-exact @fission-ai/openspec@ ``` Enable only specifically required scripts after review. 7. Perform installation in a minimally privileged development environment or sandbox. Do not run the installation as root or with `sudo`. 8. Establish an explicit dependency-update process so version changes are reviewed and tested rather than silently inherited through the mutable `latest` tag. ]]>
