Supply Chain Dependency Security

Dependency and lockfile supply-chain security review with 2025–2026 attack campaign patterns. Use when reviewing package.json, pyproject.toml, requirements.txt, pixi.toml, conda-lock.yml, or any lockfile; when evaluating a new dependency for addition; or when responding to a supply-chain compromise incident. Contains patterns for detecting maintainer-account-takeover style attacks that CVE scanners miss.

uw-ssec 4246b94 2.8 KB Updated

File contents

uw-ssec/rse-plugins/tree/main/plugins/supply-chain-security/skills/supply-chain-dependency-security commit 4246b94abf

Frequently asked questions

npx skillmds add uw-ssec/supply-chain-dependency-security