jlevy/supply-chain-hardening

Supply-chain payloads run at install, import, or repo-open time. Copy-pasteable hardening playbooks, zero-dep audit scripts, and an incident watch list for all three moments — npm, PyPI, crates.io, Go, CI/CD, and AI agent workspaces.

5Stars on the repository
6Mods indexed here, across every type
24d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

SessionStart

01

jlevy/supply-chain-hardening

Hook Claude Code

Runs when a session starts, executing ensure-gh-cli.sh and tbd-session.sh via bash (2 commands). From jlevy/supply-chain-hardening.

5 24d ago A tokens not measured copy · 100% MIT

PostToolUse

02

jlevy/supply-chain-hardening

Hook Claude Code

Runs after a tool call finishes for Bash tool calls, executing tbd-closing-reminder.sh via bash. From jlevy/supply-chain-hardening.

5 24d ago A tokens not measured original MIT

PreCompact

03

jlevy/supply-chain-hardening

Hook Claude Code

Runs before the context is compacted, executing tbd-session.sh via bash with --brief. From jlevy/supply-chain-hardening.

5 24d ago A tokens not measured copy · 100% MIT