T08 · Insecure Dependencies
- Location
SKILL.md:215- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
pdf2image== ``` 2. Maintain dependencies in a lockfile generated from a reviewed environment. 3. Require package hashes, for example through a hash-locked requirements file and: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Explicitly use a trusted package index and prevent unintended fallback to untrusted extra indexes. 5. Review and pin transitive dependencies as well as direct dependencies. 6. Recommend installation inside an isolated virtual environment or restricted container. 7. Warn users not to install dependencies with administrator or root privileges. 8. Add automated dependency vulnerability and provenance checks to the release process. ]]>
