T08 · Insecure Dependencies
- Location
SKILL.md:128- Finding
Unpinned and Unnecessary Third-Party Dependencies
- Content
View full analysis
- Remediation
View remediation
requests== ``` 3. Generate and verify cryptographic hashes, for example with `pip-tools`, and install using: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Pin and review transitive dependencies through a lock file. 5. Run dependency vulnerability and provenance checks in CI. 6. Install dependencies inside a dedicated, non-privileged virtual environment rather than into a system Python environment. 7. Periodically update pins through an explicit review process rather than automatically accepting the newest releases. ]]>
