T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
- Remediation
View remediation
anthropic== google-generativeai== ``` 2. Lock all transitive dependencies rather than only direct dependencies. Use a tool such as `pip-tools`, Poetry, or another reproducible dependency resolver. 3. Generate and verify cryptographic hashes, then install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Explicitly use a trusted package index where operationally appropriate, and avoid unreviewed extra indexes: ```bash python3 -m pip install --index-url https://pypi.org/simple --require-hashes -r requirements.txt ``` 5. Retain the documented virtual-environment workflow and advise users not to install the dependencies with administrator or root privileges. 6. Review dependency updates before changing locked versions, including transitive dependency changes and relevant security advisories. 7. Update both `SKILL.md` and `README.md` so users consistently follow the hardened installation procedure. ]]>
