T08 · Insecure Dependencies
- Location
index.js:198- Finding
Unpinned Python Dependencies Installed During Setup
- Content
View full analysis
- Remediation
View remediation
pathvalidate== ``` 2. Generate a locked requirements file that includes all transitive dependencies. 3. Record trusted SHA-256 hashes and install with: ```bash pip install --require-hashes -r requirements.txt ``` 4. Review and update the lock file through a controlled dependency-update process. 5. Prefer prebuilt, verified wheels and reject unexpected source builds where practical. 6. Continue requiring explicit user approval before setup, while clearly disclosing that third-party installation code runs with the Agent user's privileges. ]]>
