Claude resources tagged “supply-chain”
15 curated Claude Code resources tagged supply-chain in the HeyClaude directory — mostly hooks, commands, and skills. 1 of them sits in the trusted tier.
Highlights from this set
Standout entries tagged supply-chain, picked by their own metadata — trust tier, provenance, documentation, and recency.
All supply-chain resources
/dependency-risk-review - Dependency Risk Review Command for Claude Code
Rank dependency supply-chain risk from OpenSSF Scorecard health signals and OSV advisories, with actions.
/pr-security-review - PR Security Review Command for Claude Code
Review a PR diff for auth, injection, secrets, and dependency security regressions before merge.
Dependency Update Review Rules
Review dependency updates with changelog evidence, lockfile checks, vulnerability triage, compatibility tests, and supply-chain risk notes.
Dependency Update Triage Agent
Triage dependency update PRs with release evidence, lockfile review, advisories, Scorecard signals, tests, and merge recommendations.
GitHub Artifact Attestation Provenance Capability Pack Skill
Review GitHub artifact attestations, workflow provenance, digests, and release evidence.
Lockfile Provenance Checker - Claude Code Hook
Flag npm lockfile entries resolved outside the public registry or missing an integrity hash.
ORT Dependency License Checker - Claude Code Hook
Warn on dependency manifest changes and optionally run ORT license analysis before dependency-license drift reaches a PR.
Package Download Checksum Guard - Claude Code Hook
Block package and archive downloads unless the proposed Bash command includes sha256sum, shasum, Cosign, GPG, or Minisign verification.
Package Lock Risk Detector Hook for Claude Code
Detect risky lockfile edits after Write/Edit with registry host and dependency delta checks.
Package Provenance Checks Before Installing MCP Servers
Verify MCP package provenance and publisher trust before adding servers to Claude Code.
Pinning MCP Server Packages Before Installation
Pin MCP server package versions and verify registry entries before Claude Code installation.
Secure Claude Code Workstation
Defense-in-depth bundle of secret, dependency, audit, and MCP hardening entries for an agentic Claude Code setup.
SLSA Provenance Review Capability Pack Skill
Review source and artifact provenance with SLSA expectations, revision checks, builder checks, and risk-aware intake decisions.
Signal coverage
How these 15 resources score on the trust and safety signals HeyClaude reviews — counted from this set, not the directory as a whole.
A short, calm digest of reviewed Claude resources. Unsubscribe any time.