T08 · Insecure Dependencies
- Location
clawhub.json:4- Finding
Security-Sensitive Third-Party Dependencies Are Unpinned
- Content
View full analysis
- Remediation
View remediation
simmer-sdk== ``` 2. Generate a hash-locked requirements file using a tool such as `pip-compile --generate-hashes`. 3. Install with hash enforcement: ```bash pip install --require-hashes -r requirements.txt ``` 4. Lock and review transitive dependencies rather than controlling only direct packages. 5. Verify package publisher identity and provenance before updates. 6. Run dependency vulnerability and integrity scanning in CI. 7. Test dependency updates in an isolated environment before publishing a new Skill version. 8. Where supported, restrict the trading API key to the minimum account permissions and financial limits required by this Skill. ]]>
