T08 · Insecure Dependencies
- Location
scripts/wiki-lint.sh:307- Finding
Unpinned Package Download and Execution Through npx
- Content
View full analysis
/dev/null 2>&1; then NPX_BIN="npx" elif [ -x "${VOLTA_HOME:-$HOME/.volta}/bin/npx" ]; then NPX_BIN="${VOLTA_HOME:-$HOME/.volta}/bin/npx" elif [ -x "${NVM_DIR:-$HOME/.nvm}/current/bin/npx" ]; then NPX_BIN="${NVM_DIR:-$HOME/.nvm}/current/bin/npx" elif [ -d "${NVM_DIR:-$HOME/.nvm}/versions/node" ]; then _nvm_latest=$(/bin/ls -1d "${NVM_DIR:-$HOME/.nvm}/versions/node/"v* 2>/dev/null | sed 's/.*\/v//' | sort -t. -k1,1n -k2,2n -k3,3n | tail -1) _nvm_latest="${NVM_DIR:-$HOME/.nvm}/versions/node/v$_nvm_latest" [ -x "$_nvm_latest/bin/npx" ] && NPX_BIN="$_nvm_latest/bin/npx" elif [ -x "$HOME/.nix-profile/bin/npx" ]; then NPX_BIN="$HOME/.nix-profile/bin/npx" fi if [ -n "$NPX_BIN" ] && [ -f "$MDL_CONFIG" ]; then _mdl_opts=() $FIX_MODE && _mdl_opts+=(--fix) _mdl_tmp=$(mktemp) find "$WIKI" -type f -name '*.md' ! -path "$WIKI/index.md" ! -path "$WIKI/log.md" -print0 2>/dev/null | xargs -0 "$NPX_BIN" --yes markdownlint-cli2 "${_mdl_opts[@]}" --config "$MDL_CONFIG" > "$_mdl_tmp" 2>&1 ``` ### Technical Analysis The lint workflow invokes `npx --yes markdownlint-cli2` without specifying an exact package version, using a committed lockfile, or verifying package integrity. If the package is not already available locally, `npx` can retrieve the current registry version and immediately execute it without interactive confirmation. Consequently, the code that executes during linting is not fully represented by the audited project. Its effective behavior may change when the registry package is updated. A compromised package release, registry account, package resolution path, or upstream dependency could therefore introduce arbitrary code ...[truncated 1283 chars]- Remediation
View remediation
