Supply Chain Incident Response

Incident-response runbook for supply-chain compromises. Use when an advisory, CVE, GHSA, or campaign report names a dependency or GitHub Action this project uses; when responding to a Shai-Hulud-style maintainer takeover; or when a TeamPCP-style tag hijack is reported. Walks the lockfile-check → CI-cache-check → secret-rotation → persistence-artifact-hunt 4-point check end-to-end.

uw-ssec a0bfdcb 5 files · 19.0 KB Updated

File contents

uw-ssec/rse-plugins/tree/main/plugins/supply-chain-security/skills/supply-chain-incident-response commit a0bfdcb48d

Frequently asked questions

npx skillmds add uw-ssec/supply-chain-incident-response