Reusable supply-chain guardrail templates for repositories.
templates/scripts/check-supply-chain-iocs.sh- Non-npm IOC gate for Python/non-npm repos.
templates/scripts/check-supply-chain-iocs.mjs- npm/package-lock IOC gate.
templates/github-actions/supply-chain-gate-step.yml- CI job step snippet.
templates/github-actions/monthly-audit.yml- Scheduled audit workflow scaffold.
- Copy the right gate script into your repo.
- Add a CI gate step right after checkout.
- Run the gate before dependency install where practical.
- Fail CI on IOC matches.
Current defaults include:
[email protected][email protected][email protected]sfrclak.com142.11.206.73com.apple.act.mond/tmp/ld.py6202033.vbs6202033.ps1
Update patterns as new advisories are confirmed.