Dependency Supply Chain Security

Implements end-to-end software dependency supply chain security including SBOM generation (SPDX/CycloneDX), SLSA attestation levels, exact version pinning, Sigstore/cosign verification, CI scanning pipelines, transitive vulnerability management, and reproducible build patterns.

paulpas faf57e4 39.6 KB Updated

File contents

paulpas/agent-skill-router/tree/main/skills/coding/dependency-supply-chain-security commit faf57e40c8

Frequently asked questions

npx skillmds@latest add paulpas/dependency-supply-chain-security