T08 · Insecure Dependencies
- Location
SKILL.md:43- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
``` 2. Generate and enforce cryptographic hashes, for example through a hash-locked requirements file: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Commit dependency metadata and a lockfile that includes all transitive dependencies. 4. Install dependencies in a dedicated virtual environment rather than the system Python environment. 5. Use an explicitly configured, trusted package index and disable unintended extra indexes to reduce dependency-confusion exposure. 6. Run dependency vulnerability and integrity checks in CI before publishing the skill. 7. Include the referenced pipeline source and `qbo-client` dependency metadata in the reviewed artifact so their credential handling, data access, cache behavior, and input validation can be audited. ]]>
