T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Global Installation of a Third-Party CLI Package
- Content
View full analysis
- Remediation
View remediation
``` 2. Prefer a project-local dependency over global installation, and commit the generated lockfile so that package resolution is reproducible. 3. Use `npm ci` for repeatable installation from a reviewed lockfile where applicable. 4. Verify package provenance, publisher identity, release signatures or attestations, and expected integrity metadata before recommending installation. 5. Review the package's dependency tree and npm lifecycle scripts before approving a version. 6. If global installation is operationally necessary, pin the exact version, avoid elevated privileges, and document a controlled upgrade and security-review process. 7. Consider disabling lifecycle scripts during initial inspection with `--ignore-scripts`, then enable them only after confirming that required scripts are trustworthy. ]]>
