T08 · Insecure Dependencies
- Location
SETUP.md:14- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
--hash=sha256: ``` 3. Instruct users to install dependencies with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Recommend installation inside a dedicated virtual environment rather than the user's global Python environment. 5. Use automated dependency vulnerability scanning and review dependency updates before changing the lock file. 6. Document the intended Python and dependency versions in `SKILL.md` and `SETUP.md`. ]]>
