Loading...
Loading...
Use when hardening npm supply chain, pinning dependency versions, adding .npmrc security flags, or setting up Renovate and audit workflows. Locks down install-time scripts, registries, version ranges, and CI checks.
npx skill4agent add tartinerlabs/skills depspnpm-lock.yamlbun.lockbun.lockbyarn.lockpackage-lock.json<pm>.npmrc.yarnrc.ymlbunfig.tomlrenovate.json.renovaterc.renovaterc.jsonrenovatepackage.json.github/workflows/*.ymlaudit.github/workflows/*.ymldependency-review.github/workflows/*.ymllockfilepackage.json^~| Rule | Impact | File |
|---|---|---|
| .npmrc security flags | HIGH | |
| Release quarantine | MEDIUM | |
| Version pinning | HIGH | |
| Renovate | MEDIUM | |
| Audit workflow | HIGH | |
| Dependency review | HIGH | |
| Lockfile integrity | MEDIUM | |
## Supply Chain Hardening Complete
### Applied
- [list of rules applied with brief description]
### Skipped (already configured)
- [list of rules skipped with reason]
### Manual Steps Required
- [any post-setup steps, e.g. "Run `pnpm exec husky` to reinitialise git hooks"]package.jsongh