python-supply-chain
Installation
SKILL.md
python-supply-chain
Installs layered supply-chain controls into a Python package repository on GitHub:
dependency-update automation with a freshness delay, vulnerability and secret
scanning, code scanning, ownership rules for the paths that define automation, and
SBOM/provenance artifacts. The design premise, taken from the 2025–2026 incident wave
(the Shai-Hulud npm worm, the malicious axios release spread by dependency bots,
mutable-tag action compromises), is that the attack surface is now your automation
and the first hours after a release — so no single control below is sufficient, and
bot output is treated with the same suspicion as human PRs.