BigHugger
sk Skill · HetCreep

supply-chain-audit

Software supply chain audit — dependencies (CVEs, maintenance, licenses, transitive risk), build/CI integrity (SHA-pinned actions, lockfile, CI-only release), artifact integrity (checksums, signing, SBOM). Triggers on: "/supply-chain-audit", "supply-chain-audit", "dependency audit". Run before adding a dep, before a release, or for periodic review. Reports; does not change deps unless asked.

installs 8w
0
30-day movement
starts with the next reading
Related entries
2
Connections
0
JavaScript
Host repository
HetCreep/CoalMine
Host stars
13
Host language
JavaScript