T08 · Insecure Dependencies
- Location
SKILL-EN.md:25- Finding
Unpinned External Code Installation and Execution
- Content
View full analysis
- Remediation
View remediation
``` 3. Publish and enforce a lockfile, using deterministic installation such as `npm ci`. 4. Verify release signatures, provenance, and integrity checksums before installation. 5. Audit direct and transitive dependencies and enable automated dependency scanning. 6. Avoid package lifecycle scripts where they are unnecessary, for example by initially inspecting dependencies with lifecycle scripts disabled. 7. Vendor the executable source into the audited package or separately audit the exact external revision before execution. 8. Run the installed software with minimum privileges and expose only the environment variables required for the task. ]]>
