T08 · Insecure Dependencies
- Location
SETUP.md:15- Finding
Mutable and Unverified Third-Party Dependencies
- Content
View full analysis
- Remediation
View remediation
``` 2. Pin Redis to a reviewed version and digest rather than `redis:alpine`. 3. Pin the Python package to an audited version: ```bash pip install --require-hashes -r requirements.lock ``` 4. Maintain a lock file containing exact versions and SHA-256 hashes. 5. Download the SearXNG configuration from a fixed commit rather than `master`. 6. Verify downloaded files using an independently published checksum or signature. 7. Review dependency updates before changing pinned versions. 8. Apply container hardening, including a read-only root filesystem, dropped Linux capabilities, `no-new-privileges`, resource limits, and narrowly scoped writable volumes. 9. Pin and verify all dependencies before enabling automatic restart or system-wide service persistence. ]]>
