🧠 D: DOCUMENT — Problem & Opportunity
What is the problem, limitation, or opportunity? Why does this matter for SKaiNET?
Explain the context in clear terms:
- What functionality is missing or insufficient?
- Why is this important now?
- Who benefits (users, developers, researchers)?
- What is the high-level goal of this proposal?
Currently, two npm install commands pin the pachage by tag. This is a potential security vulnerability, against best practises, and lowers the OpenSSF Score. We therefore want to pin them with their commit hashes instead.
Summary (1–2 sentences):
Provide a concise overview of what this issue aims to address.
This issue addresse the potential security threat caused by packages pinned with tags.
🔍 A: ASSESS — Feasibility & Impact
Provide an evaluation of the proposal. Address the following:
✔️ Feasibility
- Is the feature straightforward to implement?
- Are there architectural constraints?
It is straightforward to switch from pinned tags to pinned commit hashes.
✔️ Expected Impact
- How does this improve SKaiNET?
- Does it unlock new capabilities?
It improves SKaiNET by improving it's security.
✔️ Risks / Constraints
- Technical challenges?
- Numerical stability concerns?
- API consistency?
None.
✔️ Dependencies
- Does this rely on an existing SKaiNET module?
- Does it require third-party libraries or standards?
None.
📚 R: RESEARCH — What Must Be Understood First?
Document research tasks or open questions that must be answered before implementation:
Research Tasks
Not applicable.
Open Questions
List unknowns that contributors should discuss or resolve.
There are no open questions.
🛠️ C: CODE — Implementation Plan
Break down actionable steps required to deliver this feature:
Development Tasks
Acceptance Criteria
💬 Additional Notes
Add diagrams, pseudo-code, references, or implementation notes that may help future contributors.
🧠 D: DOCUMENT — Problem & Opportunity
What is the problem, limitation, or opportunity? Why does this matter for SKaiNET?
Explain the context in clear terms:
Currently, two
npminstall commands pin the pachage by tag. This is a potential security vulnerability, against best practises, and lowers the OpenSSF Score. We therefore want to pin them with their commit hashes instead.Summary (1–2 sentences):
This issue addresse the potential security threat caused by packages pinned with tags.
🔍 A: ASSESS — Feasibility & Impact
Provide an evaluation of the proposal. Address the following:
✔️ Feasibility
It is straightforward to switch from pinned tags to pinned commit hashes.
✔️ Expected Impact
It improves SKaiNET by improving it's security.
✔️ Risks / Constraints
None.
✔️ Dependencies
None.
📚 R: RESEARCH — What Must Be Understood First?
Document research tasks or open questions that must be answered before implementation:
Research Tasks
Not applicable.
Open Questions
There are no open questions.
🛠️ C: CODE — Implementation Plan
Break down actionable steps required to deliver this feature:
Development Tasks
Dockerfileindocsdocumentation.ymlAcceptance Criteria
Dockerfileindocsdocumentation.yml💬 Additional Notes