T08 · Insecure Dependencies
- Location
README.md:8- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
``` 2. Generate and record SHA-256 hashes for all required distributions, then install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Commit the reviewed requirements or lockfile to the Skill package so dependency resolution is reproducible. 4. Recommend installation inside a dedicated virtual environment rather than the system Python environment: ```bash python3 -m venv .venv . .venv/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` 5. Use a trusted package index explicitly where appropriate, review dependency updates before changing the pin, and automate vulnerability and integrity checks in the release process. 6. Avoid recommending installation or execution with administrative or root privileges. ]]>
