T08 · Insecure Dependencies
- Location
rules/themes.md:27- Finding
Unpinned Packages and Arbitrary Theme Sources Enable Supply-Chain Compromise
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15;rules/getting-started.md:13-23, 120;rules/themes.md:27-37;rules/export.md:163
Vulnerability Type: Unpinned and insufficiently verified third-party dependencies
Risk Level: MediumVulnerable Code Snippets
SKILL.md:15:bash pnpm create slidev # scaffold a new deck (also: npm init slidev)rules/getting-started.md:13-23:bash # pnpm (recommended) pnpm create slidev # npm npm init slidev # yarn yarn create slidev # bun bun create slidevrules/getting-started.md:120:bash pnpm add slidev-theme-seriph # optional; installed on first run toorules/themes.md:27-37:yaml --- theme: slidev-theme-geist ---yaml --- theme: user/repo ---rules/export.md:163:yaml - run: npm installTechnical Analysis
The Skill recommends executing package-manager scaffolding and installation commands without pinning exact package versions or requiring integrity verification. It also permits themes to be loaded from arbitrary community npm package names and GitHub repository shorthand.
Package-manager commands such as
pnpm create slidev,npm init slidev, andpnpm add slidev-theme-seriphresolve mutable package releases at execution time. Consequently, the code executed by a future user can differ from the code available when this Skill was audited. Installation and build processes may execute package lifecycle scripts, build plugins, theme modules, and their transitive dependencies with the privileges of the developer or CI runner.The
theme: user/repopattern expands the trust boundary further by allowing a repository outside a verified package scope to become an executable build dependency. A malicious, compromised, or incorrectly named repository could supply arbitrary JavaScript executed during dependency installation, Slidev startup, or pres ...[truncated 2583 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin scaffolding and installed packages to reviewed exact versions:
bash pnpm create slidev@REVIEWED_VERSION pnpm add --save-exact slidev-theme-seriph@REVIEWED_VERSION -
Commit the package-manager lockfile and enforce it in local and CI builds:
bash npm cior:
bash pnpm install --frozen-lockfile -
Replace the GitHub Actions
npm installinstruction withnpm ci, and fail the workflow if the lockfile is missing or inconsistent. -
Restrict automatic recommendations to verified official Slidev package scopes and explicitly reviewed repositories. Warn users that community themes and addons execute code during installation or build.
-
Avoid recommending arbitrary
theme: user/reposources. If repository-based themes are necessary, pin them to a reviewed immutable commit rather than a mutable branch or repository default. -
Verify package ownership, package name, release provenance, integrity metadata, and repository identity before installation. Use registry allowlists or an internal package proxy for sensitive environments.
-
Inspect unfamiliar dependencies before allowing lifecycle scripts. Where operationally practical, perform the initial install with lifecycle scripts disabled and enable them only after review.
-
Run Slidev installation and builds in an isolated, least-privileged environment without unrelated credentials. Limit CI token permissions and expose deployment secrets only to jobs that require them.
-
Add automated dependency scanning, lockfile review, provenance verification, and alerts for maintainer or repository changes.
-
