Supply Chain

Software supply-chain defense — SBOM generation (CycloneDX/SPDX), SLSA build provenance, artifact signing with sigstore/cosign, dependency-confusion and typosquat defense, and consumer-side verification of what you pull in.

roodlicht Updated

File contents

roodlicht/accans-sec-skills/tree/main/skills/supply-chain commit a6533b8f9a

Frequently asked questions

npx skillmds@latest add roodlicht/supply-chain