supply-chain-security

bởi microsoft

Tài liệu tham khảo bảo mật chuỗi cung ứng phần mềm cho OpenSSF Scorecard, SLSA, Sigstore, SBOM và các phân loại tình trạng/tồn đọng.

npx skills add https://github.com/microsoft/hve-core --skill supply-chain-security

Supply Chain Security

This skill packages the durable software supply chain security (SSSC) reference material: open-standard catalogs, the combined capabilities inventory, and the classification taxonomies used to assess a repository's posture and turn gaps into prioritized work items.

When to use

Use this skill when you need to:

  • Assess a repository against the 27 combined supply chain capabilities from hve-core and physical-ai-toolchain.
  • Map posture against OpenSSF Scorecard, SLSA v1.0, OpenSSF Best Practices Badge, Sigstore (cosign), or NTIA SBOM minimum elements.
  • Classify a gap by adoption category, effort size, or qualitative concern level.
  • Derive work item priority and execution order from Scorecard risk levels.

Skill layout

Load the reference file for the topic you need. Each file holds the verbatim standard catalog or taxonomy.

ReferenceTopic
references/00-index.mdNavigation catalog for every reference in this skill
references/openssf-scorecard.mdOpenSSF Scorecard 20 checks with risk levels and score ranges
references/slsa-levels.mdSLSA v1.0 Build track levels L0 through L3
references/best-practices-badge.mdOpenSSF Best Practices Badge Passing, Silver, and Gold criteria
references/sigstore-maturity.mdSigstore (cosign) adoption maturity levels
references/sbom-elements.mdNTIA SBOM minimum elements and format guidance
references/capabilities-inventory.md27 combined capabilities across hve-core, PAT, and shared sets
references/adoption-categories.mdSix adoption categories, effort sizing, and concern levels
references/scorecard-check-mapping.mdFull 20-check implementation and adoption reference mapping
references/priority-derivation.mdRisk level to priority and execution order derivation

Attribution

Standard catalogs in this skill derive from their respective upstream projects. Per-reference attribution appears at the bottom of each reference file. See references/00-index.md for the consolidated attribution summary.

Thêm skills từ microsoft

oss-growth
microsoft
Cá tính tăng trưởng OSS
official
accessibility-aria-expert
microsoft
Phát hiện và sửa các vấn đề về khả năng tiếp cận trong giao diện web React/Fluent UI. Sử dụng khi xem xét mã để đảm bảo tương thích với trình đọc màn hình, sửa nhãn ARIA, đảm bảo…
official
generate-canvas-app
microsoft
[DEPRECATED — sử dụng canvas-app thay thế] Tạo một ứng dụng canvas Power Apps hoàn chỉnh.
official
django
microsoft
Các phương pháp tốt nhất cho phát triển web Django bao gồm models, views, templates và testing.
official
github-issue-creator
microsoft
Chuyển đổi ghi chú thô, nhật ký lỗi, ghi âm giọng nói hoặc ảnh chụp màn hình thành báo cáo vấn đề markdown sắc nét theo phong cách GitHub. Sử dụng khi người dùng dán thông tin lỗi, lỗi…
official
python-package-management
microsoft
Sử dụng uv để quản lý phụ thuộc và poethepoet để tự động hóa tác vụ.
official
runtime-validation
microsoft
Xác thực thời gian chạy cho các ứng dụng đã di chuyển — bao gồm chiến lược kiểm thử (giai đoạn lập kế hoạch) và thực thi kiểm thử (giai đoạn xác thực): xác minh khởi động,…
official
azure-postgres-ts
microsoft
Kết nối đến Azure Database for PostgreSQL Flexible Server bằng gói pg (node-postgres) với hỗ trợ xác thực mật khẩu và Microsoft Entra ID (không mật khẩu).
official