supply-chain

v2026.09.24

Software supply chain security. Covers dependency management, SBOM generation, package integrity verification, and CI/CD security. OWASP A03:2025. USE WHEN: user mentions "supply chain", "dependencies", "npm audit", "SBOM", "vulnerable packages", asks about "dependency scanning", "lockfiles", "Dependabot", "typosquatting", "CI/CD security" DO NOT USE FOR: license compliance - use `license-compliance`, secrets - use `secrets-management`, general OWASP - use `owasp-top-10`

GitHub
安装命令
npx skhub add claude-dev-suite/supply-chain
Markdown
SKILL.md

Supply Chain Security

OWASP A03:2025 - Software Supply Chain Failures

When NOT to Use This Skill

  • License compliance - Use license-compliance skill for SPDX and license auditing
  • Secrets in dependencies - Use secrets-management for credential issues
  • Application-level vulnerabilities - Use owasp-top-10 for code security
  • Git/GitHub operations - Use Git skills for repository management

Deep Knowledge: Use mcp__documentation__fetch_docs with technology: security for comprehensive documentation.

Key Risks

RiskImpactMitigation
Vulnerable dependenciesRCE, data breachRegular audits, auto-updates
TyposquattingMalicious code executionVerify package names
Compromised packagesBackdoors, malwareLockfiles, integrity checks
CI/CD pipeline attacksCode injection, secrets theftLeast privilege, signed commits

Dependency Auditing

Node.js

# Built-in audit
npm audit
npm audit fix
npm audit --json > audit.json

# Advanced scanning
npx snyk test
npx retire

# Auto-fix PRs
# Use Dependabot or Renovate

Python

# pip-audit
pip-audit
pip-audit --output=json

# Safety
safety check
safety check -r requirements.txt

# pip install with hash verification
pip install --require-hashes -r requirements.txt

Java

# OWASP Dependency Check
mvn dependency-check:check
./gradlew dependencyCheckAnalyze

# Snyk
snyk test --all-projects

Lockfiles

Always commit and use lockfiles:

Package ManagerLockfileInstall Command
npmpackage-lock.jsonnpm ci
yarnyarn.lockyarn install --frozen-lockfile
pnpmpnpm-lock.yamlpnpm install --frozen-lockfile
piprequirements.txt (with hashes)pip install --require-hashes
poetrypoetry.lockpoetry install --no-root
# npm - use ci in CI/CD
npm ci  # NOT npm install

# Verify integrity
npm audit signatures

SBOM Generation

Software Bill of Materials for transparency:

# CycloneDX format
npx @cyclonedx/cyclonedx-npm --output-file sbom.json

# SPDX format
npx spdx-sbom-generator

# Syft (multi-language)
syft . -o cyclonedx-json > sbom.json

Package Integrity

Subresource Integrity (SRI)

<script src="https://cdn.example.com/lib.js"
  integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/..."
  crossorigin="anonymous">
</script>

npm package verification

# Verify signatures
npm audit signatures

# Disable postinstall scripts
npm config set ignore-scripts true

# Or per-install
npm install --ignore-scripts

CI/CD Security

GitHub Actions

# Pin actions to SHA
- uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608 # v4.1.0

# Minimal permissions
permissions:
  contents: read
  packages: write

# Signed commits requirement
# Enable in repo settings: "Require signed commits"

Secrets in CI/CD

# Never echo secrets
- run: |
    # Wrong
    echo ${{ secrets.API_KEY }}

    # Right - use as env var
    env:
      API_KEY: ${{ secrets.API_KEY }}
    run: ./deploy.sh

Dependabot Configuration

# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
    open-pull-requests-limit: 10
    groups:
      dev-dependencies:
        dependency-type: "development"
    ignore:
      - dependency-name: "*"
        update-types: ["version-update:semver-major"]

Security Checklist

  • All dependencies audited regularly
  • Lockfiles committed and enforced
  • CI/CD uses npm ci / frozen lockfile
  • Dependabot/Renovate enabled
  • SBOM generated for releases
  • Package signatures verified
  • Post-install scripts disabled in CI
  • GitHub Actions pinned to SHA
  • Minimal CI/CD permissions

Anti-Patterns

Anti-PatternWhy It's BadCorrect Approach
Using npm install in CINon-deterministic buildsUse npm ci with lockfiles
Not committing lockfilesInconsistent dependenciesAlways commit package-lock.json
Ignoring audit warningsKnown vulnerabilities in prodFix or accept risk explicitly
Using wildcards in versions (^, ~)Unexpected breaking changesPin exact versions for critical deps
Running postinstall scripts blindlyMalicious code executionUse --ignore-scripts or audit first
No Dependabot/RenovateManual dependency updatesEnable automated PR creation

Quick Troubleshooting

IssueLikely CauseSolution
npm audit shows 100+ vulnerabilitiesTransitive dependenciesRun npm audit fix, check for breaking changes
Lockfile conflicts in PRDifferent npm versionsUse same npm version across team (in .nvmrc)
CI build fails after dependency updateBreaking change in minor versionPin exact versions, test before merging
Package not found during installTyposquatting or removed packageVerify package name on npmjs.com
SBOM generation failsMissing dependenciesRun npm ci before generating SBOM
Dependabot PRs failingIncompatible versionReview changelog, may need code changes

Related Skills

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/security/supply-chain

默认分支

main

最新提交

9496306

Tree SHA

fe4e2f1