T08 · Insecure Dependencies
- Location
SKILL.md:82- Finding
Execution of an Unpinned Package Through npx
- Content
View full analysis
- Remediation
View remediation
publish ``` 2. Record and review package provenance, release signatures, and registry metadata before recommending the command. 3. Prefer installing dependencies through a committed lockfile and using a clean installation mechanism that verifies locked integrity hashes. 4. Use `npx --no-install` after installing a reviewed, pinned dependency locally so the publishing command cannot silently retrieve a new package. 5. Run publishing tools in a restricted environment with minimal credentials and filesystem access. 6. Periodically review and deliberately update the pinned version rather than relying on a mutable distribution tag. ]]>
