T08 · Insecure Dependencies
- Location
SKILL.md:127- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
\ openai== \ google-genai== ``` 2. Maintain a lock file containing exact transitive dependency versions. 3. Require package hashes with `pip install --require-hashes`. 4. Install packages inside a dedicated virtual environment rather than the user's global Python environment. 5. Review release notes and package provenance before updating pinned versions. 6. Use trusted package indexes and disable unexpected supplemental indexes. 7. Run dependency vulnerability and integrity scans in the release process. 8. Expose only the API credential needed by the selected image provider rather than placing all provider credentials in the same runtime environment. ]]>
