Supply Chain Defense
When to use
This skill covers both producer and consumer sides of the software supply chain: what you build, how you prove that you built it, how you sign it, and how you verify what you consume. It complements cve-triage (triage of what is in your SBOM) and is invoked by cicd-hardening for the build-provenance side.
Triggers on:
- A question like "generate an SBOM", "set up SLSA", "how do I sign our artifacts", "are we vulnerable to dependency confusion", "cosi
[Description truncada. Veja o README completo no GitHub.]