Supply Chain Audit

Software supply chain audit — dependencies (CVEs, maintenance, licenses, transitive risk), build/CI integrity (SHA-pinned actions, lockfile, CI-only release), artifact integrity (checksums, signing, SBOM). Triggers on: "/supply-chain-audit", "supply-chain-audit", "dependency audit". Run before adding a dep, before a release, or for periodic review. Reports; does not change deps unless asked.

TheColliery Updated

File contents

TheColliery/CoalMine/tree/main/plugin/skills/supply-chain-audit commit 2a76b3273d

Frequently asked questions

npx skillmds@latest add thecolliery/supply-chain-audit