T08 · Insecure Dependencies
- Location
templates/ci-node.yml:12- Finding
Generated CI Workflows Use Mutable Actions and Unpinned Dependencies
- Content
View full analysis
- Remediation
View remediation
# v4.x.x - uses: actions/setup-node@ # v4.x.x ``` Retain the release version in a comment for maintainability. 2. Use a controlled update mechanism such as Dependabot or Renovate to propose reviewed action-SHA updates. 3. Pin Node package-manager versions in the repository's `package.json`: ```json { "packageManager": "pnpm@" } ``` Then enable and use Corepack rather than globally installing the latest package: ```yaml - run: corepack enable ``` 4. Require a supported lockfile and fail closed when none exists. Avoid the unrestricted `npm install` fallback in standardized CI. 5. For Python, generate and commit a lockfile with fully resolved versions. Where practical, use hash verification: ```bash pip install --require-hashes -r requirements-dev.lock pip install --no-deps -e . ``` 6. Review installation and build hooks because dependency installation can execute project-controlled or package-controlled code. 7. Combine dependency pinning with explicit read-only workflow permissions to limit the impact of any future supply-chain compromise. ]]>
