Provenance Action
danielroe
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
OPENAGENTSKILL / DIRECTORY
Find a skill for your next task. Explore tools for Codex, Claude Code, Cursor and more.
1–8 / 8
Candidates in this shortlist, not the full registry. GitHub stars belong to repositories, not individual skills.
Results: 8
danielroe
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
maddhruv
Dependency upgrades: outdated/vulnerable deps planned into semver waves (patch/minor batched, majors gated and changelog-read), applied incrementally with lockfiles rege…
sesori-ai
Weekly dependency update workflow for Sesori Apps Monorepo. Updates every pubspec.yaml across the bridge and client workspaces plus standalone packages, regenerates all…
mkbhardwas12
Lockfile-first scanner for compromised npm/PyPI/Maven/Cargo/Go/RubyGems packages — OSV + curated extras feed, SLSA L3, locked-container CI
laolaoshiren
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
ghostsecurity
Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity…
luochang212
Use when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli. Also use when npm publish fails…
AlemTuzlak
Use when the change intent is already settled and the agent must map what a behavior change touches before an implementation plan or any code. Use for new features, bug…