BigHugger
sk Skill · ShieldNet-360

supply-chain-security

Vet dependencies before they enter the build: typosquats, dependency confusion, malicious packages, known vulnerabilities, unlocked resolution, risky install and build hooks, EOL embedded runtimes, and the authenticity and freshness of your own release channel. Use when adding or upgrading a dependency, reviewing package manifests or lockfiles, configuring package sources or internal namespaces, or publishing a…

installs 8w
0
30-day movement
starts with the next reading
Related entries
2
Connections
0
Gosupply-chain
Host repository
ShieldNet-360/secure-vibe
Category
supply-chain
Version
2.0.0
Compatible with
when adding or upgrading a dependency, when reviewing PRs that modify package manifests or lockfiles, when configuring package sources, registries, or internal namespaces, when shipping an embedded runtime (Electron, CEF, a bundled JRE), before publishing a package or an application update
Host stars
22
Host language
Go