Skip to main content

npm-supply-chain-hygiene

Harden the npm supply chain: committed lockfiles, frozen CI installs (npm ci), integrity hashes, .npmrc registry pin, and lifecycle-script risk (preinstall/install/postinstall/prepare). Use when package-lock.json, npm ci vs npm install, ignore-scripts, postinstall malware, registry.npmjs vs private registry, package.json scripts, or npm CI cache trust is in scope — hand multi-ecosystem pins to dependency-pinning-strategies, namespace confusion to dependency-confusion, and SBOM gates to sbom-ci-enforcement.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
tomysh1337/openstarry-code
آخر نشاط في المصدر
١٧ أغسطس ٢٠٢٦ في ١٣:٣٥
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٣
التفرعات
٠

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.