T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Unpinned npm Package Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:30-34references/setup.md:7-13references/setup.md:97-109references/animations.md:343-349references/lambda.md:37-43
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumVulnerable Code
SKILL.md:30-34:bash - If not found: scaffold a new project: ```bash npx create-video@latest my-videotext `references/setup.md:7-13`: ```bash Create a new Remotion project using the official scaffolding tool: ```bash npx create-video@latest my-video cd my-video npm installtext `references/setup.md:97-109`: ```bash Verify version alignment: ```bash npm ls | grep remotionIf versions are mismatched, update all at once:
bash npm install remotion@latest @remotion/cli@latest @remotion/bundler@latestIf you use optional packages, include them in the update:
bash npm install remotion@latest @remotion/cli@latest @remotion/bundler@latest @remotion/player@latest @remotion/lambda@latest @remotion/media-utils@latest @remotion/transitions@latesttext `references/animations.md:343-349`: ```bash ### Installation ```bash npm install @remotion/transitionsEnsure the version matches your other
@remotion/*packages.text `references/lambda.md:37-43`: ```bash ### Package Installation ```bash npm install @remotion/lambdaEnsure the version matches your other
@remotion/*packages.text ### Technical Analysis The Skill instructs an Agent or user to retrieve npm packages through mutable version selectors such as `@latest`, as well as unconstrained package names. In particular, `npx create-video@latest` downloads and immediately runs the package version associated with the `latest` registry tag at invocation time. This means the effective code executed by the documented workflow can differ from the code that ...[truncated 2173 chars]- Remediation
View remediation
Remediation Suggestions
-
Replace mutable selectors such as
@latestwith exact, reviewed versions:bash npx create-video@X.Y.Z my-video npm install --save-exact remotion@X.Y.Z @remotion/cli@X.Y.Z @remotion/bundler@X.Y.Z -
Pin every Remotion package to the same exact version, including optional packages such as
@remotion/lambdaand@remotion/transitions. -
Commit a reviewed
package-lock.jsonand use reproducible installation in existing projects:bash npm ci -
Require package provenance, publisher, registry, and integrity verification before first execution or version upgrades.
-
Configure npm to use an explicitly trusted registry rather than inheriting an unverified registry configuration.
-
Where dependency lifecycle scripts are unnecessary, initially install with:
bash npm install --ignore-scriptsAny required lifecycle script should be reviewed before it is enabled.
-
Perform version upgrades as explicit, separately reviewed changes rather than automatically installing the current release.
-
Run scaffolding and installation commands in a least-privileged, isolated development environment without unrelated credentials in environment variables.
-
