Secure the software supply chain from the consume side: ingest the SBOM, triage CVEs by reachability, pin dependencies with a deliberate update cadence, verify SLSA provenance, and defend against malicious packages.
Scanned 9/23/2026
npx -y skills add mcorbett51090/RavenClaude --skill supply-chain-security --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Supply Chain Security?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/mcorbett51090-supply-chain-security)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: supply-chain-security
description: "Secure the software supply chain from the consume side: ingest the SBOM, triage CVEs by reachability, pin dependencies with a deliberate update cadence, verify SLSA provenance, and defend against malicious packages."
---
# Supply-Chain Security (consume side)
**Purpose:** secure what the software is made of.
## Enumerate
Consume the **SBOM** (from devops-cicd). Include transitive deps — you can't patch what you can't see.
## Triage by reachability
A vulnerable function you never call is lower priority. Reachability analysis prevents advisory-drowning.
## Pin + update on policy
Lockfiles + pins for reproducibility; deliberate automated-update cadence gated by tests — never blind auto-merge.
## Verify & defend
SLSA **provenance verification** for critical artifacts; defend against **typosquat / dependency-confusion** (scoped registries, scrutinize new deps + install scripts).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!