T08 · Insecure Dependencies
- Location
README.md:6- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
install goal-tracker-pro ``` 2. Document the expected npm registry and verified publisher to reduce dependency-confusion and registry-substitution risks. 3. Where supported, verify the downloaded package using an integrity hash, signed provenance, or another cryptographic verification mechanism. 4. Review the selected package version, including its lifecycle scripts and transitive dependencies, before recommending execution. 5. Establish a controlled update process in which newer versions are reviewed before the documented version is changed. 6. Consider an installation method that does not immediately execute remotely downloaded package code. ]]>
