Supply Chain Audit

Software supply chain audit — dependencies (CVEs, maintenance, licenses, transitive risk), build/CI integrity (SHA-pinned actions, lockfile, CI-only release), artifact integrity (checksums, signing, SBOM). Triggers on: "/supply-chain-audit", "supply-chain-audit", "dependency audit". Run before adding a dep, before a release, or for periodic review. Reports; does not change deps unless asked.

HetCreep fad5aa1 3 files · 4.6 KB Updated

File contents

HetCreep/CoalMine/tree/main/skills/supply-chain-audit commit fad5aa1742

Frequently asked questions

npx skillmds@latest add hetcreep/supply-chain-audit