Supply Chain Security

Vet dependencies before they enter the build: typosquats, dependency confusion, malicious packages, known vulnerabilities, unlocked resolution, risky install and build hooks, EOL embedded runtimes, and the authenticity and freshness of your own release channel. Use when adding or upgrading a dependency, reviewing package manifests or lockfiles, configuring package sources or internal namespaces, or publishing a package or application update.

ShieldNet-360 9060c1e 7 files · 39.2 KB Updated

File contents

ShieldNet-360/secure-vibe/tree/main/skills/supply-chain-security commit 9060c1e33b

Frequently asked questions

npx skillmds@latest add shieldnet-360/supply-chain-security