T08 · Insecure Dependencies
- Location
README.md:56- Finding
Unpinned npx Installer Creates a Supply-Chain Execution Risk
- Content
View full analysis
- Remediation
View remediation
add \ https://github.com/timeRATE-966/zhihu-research-page-skill# ``` 2. Pin the Skill repository to a full immutable commit hash or a signed release rather than the default branch. 3. Publish SHA-256 checksums for release archives and document how users can verify them before installation. 4. Use signed Git tags or release attestations and document the expected signer identity. 5. Provide a non-executing manual installation option based on a verified archive. 6. Document the exact npm package name, publisher, and expected version so users can detect package substitution. 7. Re-audit dependencies whenever the pinned installer or repository revision changes. ]]>
