| name | secure |
| description | >- Use when this capability is needed. |
Secure
When to Use This Skill
This section covers the tools and practices for discovering and remediating security issues in code, dependencies, containers, and supply chains.
Implementation
- Start with GitHub Apps: Replace PATs with secure, auditable authentication
- Add vulnerability scanning: Catch known CVEs before they deploy
- Generate SBOMs: Document your supply chain for compliance
- Run Scorecard: Measure and improve security posture
- Layer on enforcement: Make findings actionable with Enforce patterns
Comparison
Understanding the distinction:
Litmus test: Can this be bypassed?
- If no → It's a Secure tool (finding/fixing)
- If yes → It belongs in Enforce (making mandatory)
Examples
See examples.md for code examples.
Related Patterns
References
Converted and distributed by TomeVault — claim your Tome and manage your conversions.