T08 · Insecure Dependencies
- Location
references/documentation/doc-generation-guide.md:178- Finding
Mutable and Unpinned Third-Party Tooling Creates Supply-Chain Execution Risk
- Content
View full analysis
- Remediation
View remediation
lint openapi.yaml npx --yes @redocly/cli@ build-docs openapi.yaml ``` - Prefer project-local development dependencies recorded in `package.json` and a committed lockfile. - Use `npm ci` in automation to enforce lockfile resolution. - Verify package provenance and integrity before adoption. 2. **Avoid global package installation** - Replace `npm install -g @redocly/cli` with a pinned project-local dependency. - Run the local binary through a package script or an explicitly pinned `npx` invocation. 3. **Vendor or immutably pin the Spectral ruleset** - Store a reviewed copy in the project, for example: ```bash spectral lint openapi.yaml --ruleset ./config/spectral.yaml ``` - If remote retrieval is unavoidable, reference a specific immutable commit rather than `master`, verify its checksum, and restrict outbound access in CI. 4. **Pin the Docker image by digest** - Use a reviewed immutable image reference: ```bash docker run --rm -p 127.0.0.1:8080:80 \ -e SWAGGER_JSON=/spec/openapi.yaml \ -v "$(pwd)/openapi.yaml:/spec/openapi.yaml:ro" \ swaggerapi/swagger-ui@sha256: ``` - Mount the OpenAPI file read-only and bind the preview port to localhost where remote access is unnecessary. 5. **Pin GitHub Actions to full commit SHAs** - Replace `actions/checkout@v2` with a supported release pinned to a reviewed full commit SHA. - Configure minimal workflow permissions, such as read-only repository contents unless deployment explicitly requires more access. 6. **Harden CI execution** - Do not expose unrelated secrets to documentation jobs. - Restrict job permissions and outbound network access. - Separate build and deploymen ...[truncated 169 chars]
