T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
``` 2. Generate and verify cryptographic hashes, then install with: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Explicitly use a trusted package index where appropriate: ```bash python3 -m pip install --index-url https://pypi.org/simple --require-hashes -r requirements.txt ``` 4. Install the dependency inside a dedicated virtual environment rather than the system Python environment. 5. Periodically review and update the pinned version after vulnerability and compatibility testing. 6. Update both `SKILL.md` and `references/TROUBLESHOOTING.md` so they provide the same hardened installation procedure. ]]>
