Skip to main content

supply-chain-security

Secure the software supply chain — SBOM generation, dependency provenance verification, package integrity (Sigstore/npm provenance), lockfile auditing, typosquatting detection, CI artifact signing, and dependency update policy. Use when asked about "SBOM", "software bill of materials", "supply chain attack", "dependency provenance", "Sigstore", "npm provenance", "package integrity", "typosquatting", "dependency confusion", "artifact signing", "SLSA", "slsa framework", "lockfile security", or "third-party package risk". Do NOT use for: secret scanning in code — see secret-management. Do NOT use for: runtime vulnerability scanning — see security-pipeline.

跳到安装

来源信息

仓库
yanacuti1121/Yana-AI
最近来源活动
2026年6月11日 06:01
检测到的 SKILL.md 语言
英语
星标
1
分支
0

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。