BigHugger
sk Skill · mukul975

detecting-supply-chain-attacks-in-ci-cd

Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
pythondevsecopsgithub-actionsPythonci-cd-securitydependency-pinningpipeline-securitysupply-chain-security
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python