T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned Third-Party Dependency Creates Supply-Chain Exposure
- Content
View full analysis
- Remediation
View remediation
" ``` 2. Maintain a lock file containing exact versions of all transitive dependencies. 3. Generate and enforce package hashes with `pip --require-hashes`. 4. Explicitly use the official Python package index or an organization-controlled mirror. 5. Install the dependency inside a dedicated virtual environment with minimal filesystem and environment access. 6. Review new dependency versions before updating the pin. 7. Avoid exposing `DUNE_API_KEY` to installation steps; inject it only when an audited runtime command needs it. ]]>
