Supply-chain payloads run at install, import, or repo-open time. Copy-pasteable hardening playbooks, zero-dep audit scripts, and an incident watch list for all three moments — npm, PyPI, crates.io, Go, CI/CD, and AI agent workspaces.
These files are jlevy/supply-chain-hardening's own configuration. They tell Claude Code, Codex and OpenCode how to work on this repository, so they are not mods to install elsewhere. Copy one as a starting point and replace the parts that are about this project.
AGENTS.md B 1,947 tok .claude/settings.json A — .claude/settings.json A — .claude/settings.json A — .claude/settings.json A — .agents/skills/tbd/SKILL.md A 223 tok