T08 · Insecure Dependencies
- Location
scripts/init-vitepress-site.sh:22- Finding
Unpinned VitePress Dependency Executes Mutable Registry Code
- Content
View full analysis
- Remediation
View remediation
``` - Commit `package-lock.json` and use `npm ci` for reproducible CI and deployment installations. - Review lockfile changes before accepting dependency updates. - Use automated dependency updates with mandatory review, test, and security scanning. - Consider disabling lifecycle scripts where they are unnecessary: ```bash npm ci --ignore-scripts ``` Only use this option after confirming that the project does not require legitimate lifecycle scripts. - Run installation and builds in an isolated, least-privileged environment without unrelated credentials. ]]>
