T08 · Insecure Dependencies
- Location
SKILL.md:28- Finding
Unpinned Installation from a Mutable Third-Party Git Repository
- Content
View full analysis
- Remediation
View remediation
``` 2. Prefer publishing and installing a fixed version from a trusted package registry: ```bash pip install agent-lens== ``` 3. Use package hashes and a locked dependency file where supported, and require hash verification during installation. 4. Review the package source, build configuration, installation hooks, transitive dependencies, network behavior, and handling of trace data before recommending it. 5. Run the package with least privilege in an isolated virtual environment or container. Do not install it as root or with access to unrelated secrets. 6. Establish a controlled update process in which new upstream revisions are reviewed and tested before the pinned reference is changed. ]]>
