T08 · Insecure Dependencies
- Location
clawhub.json:4- Finding
Unpinned Third-Party Dependencies Have Access to Trading Credentials
- Content
View full analysis
- Remediation
View remediation
requests== ``` 2. Generate and commit a lockfile containing transitive dependency versions. 3. Require cryptographic hashes during installation, such as with `pip install --require-hashes`. 4. Install packages only from an explicitly configured and trusted package index. 5. Verify that `simmer-sdk` is the official package and review its source and release provenance before deployment. 6. Use automated dependency scanning and controlled update review rather than accepting new releases automatically. 7. Restrict `SIMMER_API_KEY` server-side to the minimum required account, venue, transaction size, and trading permissions. 8. Use separate credentials for simulation and real trading, and rotate the credential if dependency compromise is suspected. ]]>
