T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
- Remediation
View remediation
httpx== ``` 2. Generate and verify cryptographic hashes, then install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Require installation inside a dedicated virtual environment rather than the user's global or project-wide Python environment: ```bash python3 -m venv .venv . .venv/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` 4. Commit the reviewed dependency manifest or lock file to the Skill package and update it through a controlled dependency-review process. 5. Regularly scan direct and transitive dependencies for known vulnerabilities and review package provenance before accepting upgrades. 6. Advise users not to run package installation with root or administrator privileges. ]]>
