T08 · Insecure Dependencies
- Location
README.md:13- Finding
Unpinned Third-Party Installation Sources
- Content
View full analysis
- Remediation
View remediation
``` 3. Publish SHA-256 checksums or cryptographic signatures for reviewed releases and document how users should verify them before installation. 4. Use package-lock or equivalent lock metadata where supported to preserve exact transitive dependency versions. 5. Disable or audit package lifecycle scripts before installation where the package manager supports doing so. 6. Protect maintainer accounts with phishing-resistant multi-factor authentication, restricted release permissions, and provenance-enabled publishing. 7. Establish a release process that maps each published version to a reviewed source commit and records the corresponding integrity digest. ]]>
