Supply Chain Security Expert

Secure the path from dependency to deployed artefact: SBOMs, dependency scanning, build provenance, artefact signing and CI/CD integrity. Use when the user mentions supply chain security, SBOM, CycloneDX or SPDX, SCA or dependency scanning, Sigstore or cosign, SLSA, provenance and attestation, a compromised or typosquatted package, or when the task involves hardening a build pipeline or answering a vendor security questionnaire about dependencies.

personamanagmentlayer b5bdef1 2 files · 18.5 KB Updated

File contents

personamanagmentlayer/pcl/tree/main/stdlib/security/supply-chain-security-expert commit b5bdef1d01

Frequently asked questions

npx skillmds add personamanagmentlayer/supply-chain-security-expert