jlevy/supply-chain-hardening

Supply-chain payloads run at install, import, or repo-open time. Copy-pasteable hardening playbooks, zero-dep audit scripts, and an incident watch list for all three moments — npm, PyPI, crates.io, Go, CI/CD, and AI agent workspaces.

6 files for Claude Code, Codex and OpenCode: tbd, SessionStart, PostToolUse, PreCompact and 2 more — 1,947 tokens loaded in every session.

5Stars on the repository
6Files it configures its agents with
1,947Tokens loaded in every session
3Agents configured

Instructions

Settings

Hooks

Skills

These files are jlevy/supply-chain-hardening's own configuration — they tell Claude Code, Codex and OpenCode how to work on this repository, so they are not mods to install elsewhere. Copy one as a starting point and replace the parts that are about this project.