T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party Git Dependency
- Content
View full analysis
- Remediation
View remediation
``` 2. Prefer a signed, immutable release from a trusted package registry when available. 3. Verify package hashes or other integrity metadata during installation. 4. Review the pinned dependency source, including build and installation hooks, before approving it. 5. Use automated dependency monitoring to identify security advisories and intentional pin updates. 6. Run the CLI under a dedicated, least-privileged operating-system account. 7. Configure an agent-specific WeKan account with only the board permissions required for its tasks; avoid administrative tokens. 8. Rotate `WEKAN_TOKEN` immediately if dependency compromise is suspected, and review WeKan audit records for unauthorized activity. ]]>
