T08 · Insecure Dependencies
- Location
README.md:28- Finding
Unpinned Third-Party Package and Installer Execution
- Content
View full analysis
npx shadcn@latest add button card input ``` `references/dark-mode.md:118` ```bash pnpm dlx shadcn@latest add dropdown-menu ``` ### Technical Analysis The documented setup procedure instructs users or an executing agent to download and run third-party package code without pinning it to immutable, previously reviewed versions. The `@latest` selector resolves to whichever package release is current at execution time. Similarly, dependency installation without exact versions delegates version resolution to current registry metadata and semver behavior. The GitHub-based installation command refers to a mutable repository path rather than a verified commit hash. Commands such as `npx` and `pnpm dlx` execute downloaded package code directly. Package installation can also execute lifecycle scripts. Consequently, the code that runs when a user follows these instructions can differ from the code available when the Skill was ...[truncated 1864 chars]- Remediation
View remediation
init pnpm dlx shadcn@ add dropdown-menu npx clawhub@ install tailwind-v4-shadcn ``` 2. Pin regular dependencies to exact versions rather than relying on mutable registry resolution: ```bash npm install --save-exact tailwindcss@ @tailwindcss/vite@ pnpm add --save-exact tailwindcss@ @tailwindcss/vite@ pnpm add --save-exact -D @types/node@ tw-animate-css@ ``` 3. Replace the mutable GitHub tree reference with an immutable, verified commit or release artifact. Verify the source owner and commit before use. 4. Commit and enforce an appropriate lockfile, such as `package-lock.json` or `pnpm-lock.yaml`, and use reproducible installation modes in automation: ```bash npm ci pnpm install --frozen-lockfile ``` 5. Verify registry provenance and integrity metadata for all executed packages. Where supported, require signed provenance and audit unexpected publisher or ownership changes. 6. Review package lifecycle scripts before installation. In sensitive environments, initially install with lifecycle scripts disabled and explicitly approve only the scripts that are required: ```bash npm install --ignore-scripts ``` 7. Run third-party initialization tools in an isolated working copy or restricted development container with no production credentials, cloud tokens, SSH agents, or unrelated host directories available. 8. Document the reviewed versions directly in every setup and reference file so that users do not fall back to the mutable examples elsewhere in the Skill. ]]>
