T08 · Insecure Dependencies
- Location
references/tooling-tips.md:83- Finding
Unpinned Third-Party Package Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
``` 3. Use a hash-pinned requirements file and install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Record and review all transitive dependencies through a reproducible lock file. 5. Install the tool in a dedicated virtual environment with no unnecessary credentials or sensitive environment variables: ```bash python3 -m venv .venv-qmd . .venv-qmd/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` 6. Prefer signed releases or artifacts obtained through the publisher's verified canonical installation channel. 7. Review package source and installation metadata before updating the pinned version. 8. If package identity and provenance cannot be established, remove the installation instruction or replace it with a locally audited alternative. ]]>
