T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Ambiguous and Unpinned YAML Dependency Creates Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
``` 2. Select a currently supported version after reviewing its published security advisories. 3. Use a lockfile or hash-checked requirements file, for example: ```text PyYAML== --hash=sha256: ``` 4. Install dependencies with hash enforcement: ```bash pip install --require-hashes -r requirements.txt ``` 5. Use a trusted package index and prevent unreviewed fallback indexes. 6. Generate a software bill of materials and scan dependencies in CI. 7. Update `SKILL.md`, which currently claims that no external packages are required. ]]>
