T08 · Insecure Dependencies
Warning
- Location
SKILL.md:21- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
- Remediation
View remediation
# or pnpm add --save-exact orbcafe-ui@ ``` 2. Commit the generated lockfile and require deterministic installation with `npm ci` or `pnpm install --frozen-lockfile`. 3. Review the package's source, maintainer history, transitive dependencies, and lifecycle scripts before approving it. 4. Validate package integrity through the lockfile and trusted registry controls. 5. Run dependency installation in a restricted environment without production secrets or unnecessary filesystem permissions. 6. Add automated dependency and supply-chain scanning to detect compromised, deprecated, or unexpectedly changed packages. 7. Establish a controlled update process so new versions are reviewed and tested before adoption. ]]>
