Supply Chain Audit

Reviews software supply chain security — dependency vulnerabilities, lockfile pinning, SBOM generation, build reproducibility, base image hygiene, commit signing, secret scanning in history, and CI/CD pipeline integrity. Use when the user asks about "supply chain", "dependencies", "SBOM", "vulnerabilities", "CVEs", "dependency security", invokes /supply-chain-audit, or when the orchestrator delegates. Stack-agnostic, mode-aware, scope-tier-aware.

Nordic-AI Updated

File contents

Nordic-AI/production-readiness-skills/tree/main/skills/supply-chain-audit commit b494636e27

Frequently asked questions

npx skillmds@latest add nordic-ai/supply-chain-audit