Supply Chain Security

Establishes trust in what you build and ship — SBOMs, build provenance, dependency pinning and verification, artifact signing, and signature verification before deploy. Use this whenever the user is asking what's inside their build, wants to pin or verify a dependency, is setting up artifact signing or SLSA provenance, is deciding whether to trust a third-party package, or is hardening a release pipeline against tampering. For patching what a scan finds use `vulnerability-management`; for the CI system producing these builds use `pipeline-security`.

arjunprabhulal Updated

File contents

arjunprabhulal/devops-skills/tree/main/skills/security/supply-chain-security commit 1d333a6e8c

Frequently asked questions

npx skillmds@latest add arjunprabhulal/supply-chain-security