T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
- Remediation
View remediation
' ``` 2. Maintain a locked requirements file with package hashes and install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Verify the package's official registry namespace and document the expected publisher and source repository. 4. Review the pinned package and its transitive dependencies before updating. 5. Install the package in an isolated virtual environment rather than the user's global Python environment. 6. Run the service as a non-privileged account and grant it access only to explicitly approved search directories. 7. Protect `~/.sirchmunk/.env` with restrictive file permissions and use a narrowly scoped LLM API key. ]]>
