T08 · Insecure Dependencies
- Location
README.md:143- Finding
Unpinned Global Installation of a Credential-Handling Third-Party CLI
- Content
View full analysis
- Remediation
View remediation
``` 2. Avoid global installation. Install the package in a dedicated project directory and execute the pinned local binary. 3. Commit and verify an npm lockfile containing package integrity hashes. 4. Review the pinned package, its lifecycle scripts, and transitive dependencies before recommending it. 5. Disable unnecessary npm lifecycle scripts during installation where compatible: ```bash npm install --ignore-scripts ``` 6. Run the CLI in an isolated environment with access only to required credentials and files. 7. Document the package source, reviewed version, expected checksum, and upgrade-review procedure. 8. Encourage users to use a dedicated Twitter/X account or short-lived session rather than a high-value primary account. ]]>
