T08 · Insecure Dependencies
- Location
SKILL.md:57- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
- Remediation
View remediation
``` 2. Prefer a project-local dependency and invoke it through a package script or `npx --no-install` instead of installing it globally. 3. Commit and verify an npm lockfile so transitive dependency versions remain reproducible. 4. Verify the official package name, publisher, registry source, and package integrity before installation. 5. Disable lifecycle scripts during installation where operationally possible: ```bash npm install --ignore-scripts ``` 6. Run third-party tooling with a minimally privileged account and avoid elevated global installation. ]]>
