Supply Chain Security

Secure the software supply chain — SBOM generation, dependency provenance verification, package integrity (Sigstore/npm provenance), lockfile auditing, typosquatting detection, CI artifact signing, and dependency update policy. Use when asked about "SBOM", "software bill of materials", "supply chain attack", "dependency provenance", "Sigstore", "npm provenance", "package integrity", "typosquatting", "dependency confusion", "artifact signing", "SLSA", "slsa framework", "lockfile security", or "third-party package risk". Do NOT use for: secret scanning in code — see secret-management. Do NOT use for: runtime vulnerability scanning — see security-pipeline.

yanacuti1121 730a7f3 5.7 KB Updated 2 repo stars

File contents

yanacuti1121/Yana-AI/tree/main/core/skills/supply-chain-security commit 730a7f3e4b

Frequently asked questions

npx skillmds add yanacuti1121/supply-chain-security