Supply Chain

Use when securing the software supply chain — dependencies, build pipelines, and artifact integrity. Covers SBOMs, dependency scanning, SLSA framework, artifact signing, and reproducible builds. USE FOR: SBOM, software bill of materials, dependency scanning, SLSA framework, artifact signing, reproducible builds, SCA, Dependabot, Snyk, Trivy, Grype, CycloneDX, SPDX DO NOT USE FOR: runtime vulnerability detection (use security-testing), container runtime security (use security-testing), secrets in code detection (use security-testing)

Tyler-R-Kendrick 231c034 14 files · 26.9 KB Updated

File contents

Tyler-R-Kendrick/agent-skills/tree/main/skills/security/supply-chain commit 231c034668

Frequently asked questions

npx skillmds add tyler-r-kendrick/supply-chain