T08 · Insecure Dependencies
- Location
package.json:15- Finding
Unpinned npm Dependencies Permit Unreviewed Supply-Chain Changes
- Content
View full analysis
npm install ``` ### Technical Analysis All three runtime dependencies use caret version ranges. The project also lacks a committed `package-lock.json`. Consequently, `npm install` can resolve package versions and transitive dependency trees that differ from those reviewed during this audit. A future package release satisfying one of these ranges could introduce malicious or vulnerable code. Installation can also run npm lifecycle scripts and native build operations. The documentation specifically notes that `sharp` may compile during installation, demonstrating that dependency installation is expected to perform executable build activity. No reviewed dependency was proven malicious. The vulnerability is the absence of deterministic dependency resolution and integrity-controlled installation, which exposes users to future registry compromise, maintainer compromise, malicious compatible releases, and unexpected transitive dependency changes. ### Attack Path 1. An attacker compromises a direct or transitive dependency maintainer account, npm publishing token, or package release process. 2. The attacker publishes a malicious version that satisfies one of the declared caret ranges, or introduces a malicious transitive dependency through such a release. 3. A user follows `SKILL.md` and runs `npm install`. 4. Because no reviewed lockfile constrains versions and integrity hashes, npm resolves and installs the newly published package tree. 5. Malicious code exec ...[truncated 850 chars]- Remediation
View remediation
