T08 · Insecure Dependencies
- Location
SKILL.md:33- Finding
Unpinned Third-Party Package Download and Execution
- Content
View full analysis
- Remediation
View remediation
install ``` 2. Replace the mutable plugin declaration with the same exact version: ```json { "plugin": ["oh-my-opencode@"] } ``` 3. Publish the expected package digest, lockfile entry, or registry integrity value and require verification before execution. 4. Review release provenance and use signed releases or trusted publishing attestations where available. 5. Avoid automatic updates to `latest`; require an explicit review and approval process for each upgrade. 6. Run installation and plugin execution with least privilege, without administrative permissions, and within an appropriate sandbox where feasible. 7. Document how users can inspect the resolved package version and source before allowing it to execute. ]]>
