T08 · Insecure Dependencies
- Location
README.md:141- Finding
Unpinned Global Installation of a Privileged Third-Party CLI
- Content
View full analysis
- Remediation
View remediation
``` 2. Record and verify the expected package integrity digest. 3. Prefer a project-local dependency with a committed lockfile over a global installation. 4. Document the reviewed upstream repository and package identity. 5. Resolve the executable to an explicitly configured, verified path before execution. 6. Run the CLI in a restricted environment with only the credentials and filesystem access it requires. 7. Consider replacing browser-session-cookie authentication with an official, narrowly scoped API integration. 8. Establish a dependency update process that includes source review and integrity validation before changing the pinned version. ]]>
