Supply Chain Defense

Behavioural-first defense against poisoned npm/PyPI packages in the publish-to-advisory window CVE tools miss. Use before every install or version bump: 7-day cooldown gate, Socket.dev behavioural score, stale-OIDC audit, publish-token rotation, and a worm-persistence self-scan.

0xDarkMatter Updated

File contents

0xDarkMatter/claude-mods/tree/main/skills/supply-chain-defense commit d037a8e7c1

Frequently asked questions

npx skillmds@latest add 0xdarkmatter/supply-chain-defense