NPM Supply Chain Security

Audit and harden Node.js projects against npm supply chain attacks — compromised maintainer accounts, malicious package versions, and install-script payloads. Use when reviewing or setting up package.json, lockfiles, .npmrc, Dockerfile, or CI workflows for security; when the user mentions npm security, supply chain attacks, `npm audit`, lockfile policy, install scripts, or min-release-age; also when the user wants to check whether their dependencies are safe, or recover from a suspected compromise.

nbbaier Updated

File contents

nbbaier/agent-skills/tree/main/skills/deprecated/npm-supply-chain-security commit aaa7c6651f

Frequently asked questions

npx skillmds@latest add nbbaier/npm-supply-chain-security