T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned Third-Party Payment Package Installation
- Content
View full analysis
- Remediation
View remediation
``` 3. Distribute or link to the exact source revision corresponding to the package release so that the payment implementation can be independently audited. 4. Use reproducible builds and sign release artifacts or attestations. 5. Recommend installation in a dedicated virtual environment with only the permissions required for browser injection and keychain access. 6. Verify publisher identity and package provenance before installation. 7. Add an upgrade procedure requiring review and integrity verification before changing the pinned version. ]]>
