T08 · Insecure Dependencies
- Location
README.md:36- Finding
Unpinned Third-Party Package Execution During Installation
- Content
View full analysis
- Remediation
View remediation
add vst93/vision-fallback-skill ``` 2. Document the expected package publisher, version, and integrity hash. 3. Prefer installation through a lockfile-backed package manager workflow where feasible. 4. Provide a verified manual installation option using a signed release archive or a commit-specific repository URL. 5. Recommend reviewing installer changes before upgrading to newer versions. 6. If the installer supports signature or checksum verification, require that verification in the documented workflow. ]]>
