Dependency Supply Chain

Audit and defend against malicious dependencies in npm, pnpm, PyPI, and similar ecosystems. Covers lockfile hygiene, the limits of npm audit, behavior-level scanning with socket.dev, postinstall script review, typosquat and slopsquat detection, and minimum-permission CI runs. Invoke when adding a new dependency, after a supply-chain incident, or as periodic audit.

yanacuti1121 6f1d8b0 9.9 KB Updated 2 repo stars

File contents

yanacuti1121/Yana-AI/tree/main/core/skills/gw360--dependency-supply-chain commit 6f1d8b0ade

Frequently asked questions

npx skillmds add yanacuti1121/dependency-supply-chain