Skip to main content

npm-supply-chain-hygiene

Harden the npm supply chain: committed lockfiles, frozen CI installs (npm ci), integrity hashes, .npmrc registry pin, and lifecycle-script risk (preinstall/install/postinstall/prepare). Use when package-lock.json, npm ci vs npm install, ignore-scripts, postinstall malware, registry.npmjs vs private registry, package.json scripts, or npm CI cache trust is in scope โ€” hand multi-ecosystem pins to dependency-pinning-strategies, namespace confusion to dependency-confusion, and SBOM gates to sbom-ci-enforcement.

Jump to install

Source facts

Repository
tomysh1337/openstarry-code
Last source activity
August 17, 2026 at 13:35
Detected SKILL.md language
English
Stars
3
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.