Skill: Supply Chain Hygiene (CWE-295, CWE-494)
- Image references without a digest pin (
image: foo:latestis a violation; require@sha256:...). InsecureSkipVerify: true, TLS verification bypass, or--insecureflags.replacedirectives ingo.modwithout a tracked issue and a target removal version.curl | sh,wget | bash, or scripts fetched from a URL inside a Dockerfile or Makefile.- Third-party GitHub Actions / CI workflow steps pinned to a moving tag instead of a commit SHA.
- New direct dependencies without a one-line justification.