T08 · Insecure Dependencies
- Location
README.md:14- Finding
Unpinned Security-Sensitive Runtime Dependencies
- Content
View full analysis
- Remediation
View remediation
PyJWT== ``` 2. Generate and verify cryptographic hashes for every package and transitive dependency. 3. Document installation using hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Use an explicitly trusted package index or an internally controlled artifact repository. 5. Add automated dependency vulnerability and integrity scanning to release workflows. 6. Review and update pinned versions on a controlled schedule rather than automatically accepting the newest releases. 7. Run the Skill in a constrained environment that cannot access unrelated user files or credentials. ]]>
