Dependency Audit

Audit a project's dependency supply chain — known CVEs in installed packages, secrets about to be committed, and lockfile/provenance integrity — and wire the checks into CI as a merge gate. Use when asked to audit dependencies, check for vulnerable packages, scan for leaked secrets, add a security gate to CI, or harden the supply chain. Complements security-audit (app-level) and git-safety (git history).

shipshitdev 42bb459 2 files · 6.1 KB Updated

File contents

shipshitdev/skills/tree/main/skills/dependency-audit commit 42bb459f3e

Frequently asked questions

npx skillmds add shipshitdev/dependency-audit