Stash Supply Chain Security

Supply-chain security controls for the @cipherstash/stack monorepo. Covers post-install script policy (onlyBuiltDependencies), install cooldown (minimumReleaseAge), lockfile integrity (blockExoticSubdeps + lockfile registry check), frozen-lockfile CI, registry pinning (.npmrc), Dependabot cooldown, and CODEOWNERS. Use when modifying CI workflows, pnpm config, dependency updates, .github/dependabot.yml, or anything that touches how packages enter the build. Use when this capability is needed.

tomevault-io Updated

File contents

tomevault-io/skills-registry/tree/main/cipherstash--stack--stack commit 244c282966

Frequently asked questions

npx skillmds@latest add tomevault-io/stash-supply-chain-security